• Wrong document? Swap it for free
  • Written by students who passed
  • Immediately available after payment
  • Read online or as PDF
Sell
Where do you study
Your language
Document preview thumbnail
Preview 4 out of 48 pages
Exam (elaborations)

WGU D486 PRACTICE EXAMINATION 2026 QUESTIONS WITH ANSWERS GRADED A+

Document preview thumbnail
Preview 4 out of 48 pages

WGU D486 PRACTICE EXAMINATION 2026 QUESTIONS WITH ANSWERS GRADED A+

Content preview

WGU D486 PRACTICE EXAMINATION 2026
QUESTIONS WITH ANSWERS GRADED A+

◍ 5 steps of the operations security process.
Answer: 1.Identification of critical information2.Analysis of
threats3.Analysis of vulnerabilities4.Assessment of risks5.Application of
countermeasures
◍ residual data.
Answer: Data that is unintentionally left behind on a storage device
◍ What are the four focus areas of OpenSAMM?.
Answer: Governance, Construction, Verification, and Deployment.
◍ How can static analysis help identify SQL injection vulnerabilities?.
Answer: Static analysis can detect SQL injection vulnerabilities by
analyzing the source code for patterns where user input is directly used in
queries without validation.Injection vulnerabilities remain a top OWASP
Top 10 issue and should be mitigated by using parameterized queries and
input validation.
◍ Why is input validation critical in software security?.
Answer: All user input should be considered untrusted and must be validated
before being used to prevent injection attacks and other exploits.
◍ assessment of risks.
Answer: 4th step in the OPSEC process: to determine what issues we really
need to be concerned about (areas with matching threats and vulnerabilities)
◍ which secure coding best practice uses well-tested, publicly available
algorithms to hide product data from unauthorized access?.
Answer: cryptographic practice
◍ packet filtering.

, Answer: A firewall technology that inspects the contents of each packet in
network traffic individually and makes a gross determination (based on
source and destination IP address, port number, and the protocol being used)
of whether the traffic should be allowed to pass
◍ Remediation Report.
Answer: A ____ report/dashboard should be prepared and updated regularly
from this stage. The purpose of this report is to showcase the security
posture and risk of the product at a technical level. A4 D&D
◍ anti-malware tool.
Answer: A type of tool that uses signature matching or anomaly detection
(heuristics) to detect malware threats, either in real-time or by performing
scans of files and processes
◍ SPI (Stateful Packet Inspection).
Answer: a firewall that can watch packets and monitor the traffic from a
given connection
◍ utility.
Answer: refers to how useful the data is to us
◍ What is the goal of the SDL project outline in Security Assessment (A1)?.
Answer: To map SDL activities to the development schedule.
◍ RAID (redundant array of inexpensive disks).
Answer: a data storage virtualization technology that combines multiple
physical disk drive components into a single logical unit for the purposes of
data redundancy, performance improvement, or both.
◍ cryptography.
Answer: the science of keeping information secure
◍ something you are.
Answer: An iris scan is an example of this type of factor
◍ malware.
Answer: a security awareness issue that involves educating users about

, malicious software and how to avoid it
◍ FISMA (Federal Information Security Modernization Act).
Answer: this law provides a framework for ensuring the effectiveness of
information security controls in federal government- changed from
Management (2002) to Modernization in 2014
◍ proxy server.
Answer: a specialized type of firewall that can serve as a choke point, log
traffic for later inspection, and provides a layer of security by serving as a
single source of requests for the devices behind it
◍ bounds checking.
Answer: to set a limit on the amount of data we expect to receive to set aside
storage for that data*required in most programming languages* prevents
buffer overflows
◍ What is the next step after the PSIRT determines a vulnerability is credible
and high severity?.
Answer: Identify resources and schedule the fix
◍ Biba model.
Answer: Primarily concerned with protecting the integrity of data, even at
the expense of confidentiality. - 2 security rules: the simple integrity axiom
and the * integrity axiom
◍ A software security team member has created data flow diagrams, chosen
the STRIDE methodology to perform threat reviews, and created the
security assessment for a new product.Which category of secure software
best practices did the team member perform?.
Answer: Architecture Analysis is a best practice that helps organizations
identify security risks early in the design phase before implementation.
◍ stuxnet.
Answer: A particularly complex and impactful item of malware that targeted
the Supervisory Control and Data Acquisition (SCADA) systems that run
various industrial processes; this piece of malware raised the bar for

, malware from largely being a virtual-based attack to actually being
physically destructive
◍ Information Security.
Answer: protects information and information systems from unauthorized
access, use, disclosure, disruption, modification, or destruction
◍ SSL (secure sockets layer).
Answer: a protocol that uses the RSA algorithm (an asymmetric algorithm)
to secure web and email traffic
◍ Privacy Compliance Report.
Answer: The _________ report should provide progress against privacy
requirements provided in earlier phases. Any outstanding requirement
should be implemented as soon as possible. It is also prudent to assess any
changes in laws/regulations to identify (and put on a roadmap) any new
requirements. A4 D&D
◍ ECC (Elliptic Curve Cryptography).
Answer: An asymmetric encryption algorithm that uses smaller key sizes
and requires less processing power than many other encryption
methods.commonly used in smaller wireless devices
◍ Safety, evacuation plans, administrative controls.
Answer: Name the 3 main considerations for protecting people
◍ What are the key elements of a Data Flow Diagram (DFD) and their
symbols?.
Answer: External Element (Rectangle) – Represents an external system/user
interacting with the application.Process (Circle) – Handles data operations
or transforms input into output.Multiple Processes (Double Circle) –
Represents a collection of sub-processes functioning together.Data Store
(Two Parallel Lines) – Stores data without modification.Data Flow (Arrow)
– Represents movement and direction of data between elements.Trust
Boundary (Dashed Curve) – Marks security boundaries where privilege
levels change between components.

Document information

Uploaded on
April 10, 2026
Number of pages
48
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers
$13.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
Sold
20
Followers
0
Items
7904
Last sold
8 hours ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions