WGU D518 A3 - COLLABORATION
PRACTICE EXAMINATION 2026
QUESTIONS WITH ANSWERS GRADED A+
◍ During functional testing, a QA analyst using a non-admin account caused
an application exception. After the exception was handled, the tester was
able to navigate to the admin section of the application by typing the URL
directly into the browser address bar. They were unable to force the same
navigation before the exception was thrown. How should the organization
remediate this vulnerability?.
Answer: Ensure user privileges are restored to the appropriate level after
exceptions
◍ transparency and clarity.
Answer: elements that ensure the criteria used to assess students are clear
and understandable, making the assessment process fair and transparent
◍ flexible grouping.
Answer: a teaching strategy that allows educators to personalize instruction
to meet the unique needs of students
◍ What is the purpose of Security test plans in A3 Design & Development?.
Answer: To create a plan to mitigate, accept, or tolerate risk.
◍ What is the main difference between BSIMM and OpenSAMM?.
Answer: BSIMM is observational and focuses on benchmarking real-world
security practices from top organizations.OpenSAMM is prescriptive,
providing a structured roadmap and guidance on improving security
practices.
◍ Core Activities in OpenSAMM.
Answer: Governance – Security policy, compliance, and
, strategy.Construction – Security requirements, architecture, and
design.Verification – Code review, security testing, and
assurance.Deployment – Secure deployment, vulnerability management.
◍ What are Post-release certifications in PRSA?.
Answer: Certifications from external parties to demonstrate the security
posture of a product or service.
◍ What is the purpose of authorization in security?.
Answer: Authorization ensures that only specific users, systems, or APIs can
perform certain operations, preventing unauthorized access.
◍ Which security assessment deliverable defines milestones that will be met
during each phase of the project, merged into the product development
schedule?.
Answer: SDL project outline
◍ What does Updated policy compliance analysis ensure in A5 Ship?.
Answer: It ensures adherence to company policies.
◍ What type of model is BSIMM?.
Answer: Observational – it studies existing security practices in
organizations.
◍ What does the STRIDE threat model stand for, and what security properties
does it impact?.
Answer: STRIDE is a threat classification model used to analyze and
mitigate security risks. It consists of:Spoofing – Impersonating a user to
gain access (Authentication)Tampering – Modifying or altering data
(Integrity)Repudiation – Performing actions without traceability
(Non-repudiation)Information Disclosure – Gaining unauthorized access to
data (Confidentiality)Denial of Service (DoS) – Preventing legitimate use of
a system (Availability)Elevation of Privilege – Gaining higher access levels
without authorization (Authorization)
◍ homogenous group.
Answer: a group composed of one ability level
, ◍ Which post-release deliverable applies when evaluating a competitor’s
point-of-sale system for compliance during an acquisition?.
Answer: Security strategy and process for legacy code, M&As, and EOL
plans
◍ What is the goal of the SDL project outline in Security Assessment (A1)?.
Answer: To map SDL activities to the development schedule.
◍ The software security group is conducting a maturity assessment using the
Building Security in Maturity Model (BSIMM). They are currently focused
on reviewing security testing results from recently completed initiatives.
Which BSIMM domain is being assessed?.
Answer: Software security development life cycle (SSDL) touchpoints
◍ Code review actually happens in the ?.
Answer: In A4 (Design & Development), security testing activities
◍ Security team members have been instructed to document how many users
will access the new product and what roles those users will play. Which step
of the security test plan is being performed?.
Answer: Define the user community
◍ Which secure coding best practice says that all information passed to other
systems should be encrypted?.
Answer: Communication SecurityExplanation:Encryption in transit protects
data from eavesdropping and man-in-the-middle (MITM) attacks.Secure
communication protocols like TLS (Transport Layer Security) and HTTPS
ensure confidentiality and integrity.End-to-end encryption prevents
unauthorized access during data exchange between systems.
◍ C++.
Answer: Code written in these languages should be analyzed in depth for
buffer overflow vulnerabilities.
◍ What is the recommended way to mitigate a threat identified during threat
modeling?.
PRACTICE EXAMINATION 2026
QUESTIONS WITH ANSWERS GRADED A+
◍ During functional testing, a QA analyst using a non-admin account caused
an application exception. After the exception was handled, the tester was
able to navigate to the admin section of the application by typing the URL
directly into the browser address bar. They were unable to force the same
navigation before the exception was thrown. How should the organization
remediate this vulnerability?.
Answer: Ensure user privileges are restored to the appropriate level after
exceptions
◍ transparency and clarity.
Answer: elements that ensure the criteria used to assess students are clear
and understandable, making the assessment process fair and transparent
◍ flexible grouping.
Answer: a teaching strategy that allows educators to personalize instruction
to meet the unique needs of students
◍ What is the purpose of Security test plans in A3 Design & Development?.
Answer: To create a plan to mitigate, accept, or tolerate risk.
◍ What is the main difference between BSIMM and OpenSAMM?.
Answer: BSIMM is observational and focuses on benchmarking real-world
security practices from top organizations.OpenSAMM is prescriptive,
providing a structured roadmap and guidance on improving security
practices.
◍ Core Activities in OpenSAMM.
Answer: Governance – Security policy, compliance, and
, strategy.Construction – Security requirements, architecture, and
design.Verification – Code review, security testing, and
assurance.Deployment – Secure deployment, vulnerability management.
◍ What are Post-release certifications in PRSA?.
Answer: Certifications from external parties to demonstrate the security
posture of a product or service.
◍ What is the purpose of authorization in security?.
Answer: Authorization ensures that only specific users, systems, or APIs can
perform certain operations, preventing unauthorized access.
◍ Which security assessment deliverable defines milestones that will be met
during each phase of the project, merged into the product development
schedule?.
Answer: SDL project outline
◍ What does Updated policy compliance analysis ensure in A5 Ship?.
Answer: It ensures adherence to company policies.
◍ What type of model is BSIMM?.
Answer: Observational – it studies existing security practices in
organizations.
◍ What does the STRIDE threat model stand for, and what security properties
does it impact?.
Answer: STRIDE is a threat classification model used to analyze and
mitigate security risks. It consists of:Spoofing – Impersonating a user to
gain access (Authentication)Tampering – Modifying or altering data
(Integrity)Repudiation – Performing actions without traceability
(Non-repudiation)Information Disclosure – Gaining unauthorized access to
data (Confidentiality)Denial of Service (DoS) – Preventing legitimate use of
a system (Availability)Elevation of Privilege – Gaining higher access levels
without authorization (Authorization)
◍ homogenous group.
Answer: a group composed of one ability level
, ◍ Which post-release deliverable applies when evaluating a competitor’s
point-of-sale system for compliance during an acquisition?.
Answer: Security strategy and process for legacy code, M&As, and EOL
plans
◍ What is the goal of the SDL project outline in Security Assessment (A1)?.
Answer: To map SDL activities to the development schedule.
◍ The software security group is conducting a maturity assessment using the
Building Security in Maturity Model (BSIMM). They are currently focused
on reviewing security testing results from recently completed initiatives.
Which BSIMM domain is being assessed?.
Answer: Software security development life cycle (SSDL) touchpoints
◍ Code review actually happens in the ?.
Answer: In A4 (Design & Development), security testing activities
◍ Security team members have been instructed to document how many users
will access the new product and what roles those users will play. Which step
of the security test plan is being performed?.
Answer: Define the user community
◍ Which secure coding best practice says that all information passed to other
systems should be encrypted?.
Answer: Communication SecurityExplanation:Encryption in transit protects
data from eavesdropping and man-in-the-middle (MITM) attacks.Secure
communication protocols like TLS (Transport Layer Security) and HTTPS
ensure confidentiality and integrity.End-to-end encryption prevents
unauthorized access during data exchange between systems.
◍ C++.
Answer: Code written in these languages should be analyzed in depth for
buffer overflow vulnerabilities.
◍ What is the recommended way to mitigate a threat identified during threat
modeling?.