,WGU D487 – Secure Software Design Objective Assessment | OA V1 and V2 | Full
Questions and Answers | 2026 Updated | GUARANTEED PASS.
🔹 SECTION 1: CORE CONCEPTS (Q1–15)
Q1. What is the primary difference between software security and application security?
A. No difference
B. Software security focuses on code; application security focuses on deployment
C. Software security is built into development; application security focuses on protecting running
apps
D. Application security is broader than software security
✅ Answer: C
Q2. Which principle ensures data is not altered improperly?
A. Confidentiality
B. Availability
C. Integrity
D. Authentication
✅ Answer: C
Q3. Which control enforces confidentiality?
A. Hashing
B. Encryption
C. Checksums
D. Logging
✅ Answer: B
Q4. What model categorizes threats?
A. DREAD
B. STRIDE
C. CVSS
D. BSIMM
✅ Answer: B
,Q5. What does DREAD evaluate?
A. Threat categories
B. Risk severity
C. Compliance
D. Encryption
✅ Answer: B
Q6. Adding new APIs increases what?
A. Security posture
B. Attack surface
C. Integrity
D. Compliance
✅ Answer: B
Q7. Which is NOT part of the CIA triad?
A. Confidentiality
B. Integrity
C. Authentication
D. Availability
✅ Answer: C
Q8. Which STRIDE threat violates availability?
A. Spoofing
B. Tampering
C. DoS
D. Repudiation
✅ Answer: C
Q9. What is a key outcome of threat modeling?
A. Code execution
B. Identifying threats before coding
C. Encryption setup
D. Deployment
, ✅ Answer: B
Q10. Secure code differs from quality code because it:
A. Runs faster
B. Focuses on user experience
C. Handles threats and abuse cases
D. Uses fewer resources
✅ Answer: C
Q11. What identifies how data flows through a system?
A. STRIDE
B. DFD
C. CVSS
D. API
✅ Answer: B
Q12. Which symbol represents a process in DFD?
A. Rectangle
B. Circle
C. Arrow
D. Line
✅ Answer: B
Q13. What is the purpose of a trust boundary?
A. Store data
B. Show privilege separation
C. Encrypt data
D. Validate inputs
✅ Answer: B
Questions and Answers | 2026 Updated | GUARANTEED PASS.
🔹 SECTION 1: CORE CONCEPTS (Q1–15)
Q1. What is the primary difference between software security and application security?
A. No difference
B. Software security focuses on code; application security focuses on deployment
C. Software security is built into development; application security focuses on protecting running
apps
D. Application security is broader than software security
✅ Answer: C
Q2. Which principle ensures data is not altered improperly?
A. Confidentiality
B. Availability
C. Integrity
D. Authentication
✅ Answer: C
Q3. Which control enforces confidentiality?
A. Hashing
B. Encryption
C. Checksums
D. Logging
✅ Answer: B
Q4. What model categorizes threats?
A. DREAD
B. STRIDE
C. CVSS
D. BSIMM
✅ Answer: B
,Q5. What does DREAD evaluate?
A. Threat categories
B. Risk severity
C. Compliance
D. Encryption
✅ Answer: B
Q6. Adding new APIs increases what?
A. Security posture
B. Attack surface
C. Integrity
D. Compliance
✅ Answer: B
Q7. Which is NOT part of the CIA triad?
A. Confidentiality
B. Integrity
C. Authentication
D. Availability
✅ Answer: C
Q8. Which STRIDE threat violates availability?
A. Spoofing
B. Tampering
C. DoS
D. Repudiation
✅ Answer: C
Q9. What is a key outcome of threat modeling?
A. Code execution
B. Identifying threats before coding
C. Encryption setup
D. Deployment
, ✅ Answer: B
Q10. Secure code differs from quality code because it:
A. Runs faster
B. Focuses on user experience
C. Handles threats and abuse cases
D. Uses fewer resources
✅ Answer: C
Q11. What identifies how data flows through a system?
A. STRIDE
B. DFD
C. CVSS
D. API
✅ Answer: B
Q12. Which symbol represents a process in DFD?
A. Rectangle
B. Circle
C. Arrow
D. Line
✅ Answer: B
Q13. What is the purpose of a trust boundary?
A. Store data
B. Show privilege separation
C. Encrypt data
D. Validate inputs
✅ Answer: B