• Wrong document? Swap it for free
  • Written by students who passed
  • Immediately available after payment
  • Read online or as PDF
Sell
Where do you study
Your language
Document preview thumbnail
Preview 4 out of 69 pages
Exam (elaborations)

Wgu D487 Oa Exam – Questions Complete With 100% Verified Correct Answers 2026/2027

Document preview thumbnail
Preview 4 out of 69 pages

WGU D487 OA EXAM – QUESTIONS COMPLETE WITH 100% VERIFIED CORRECT ANSWERS 1. What is the study of real-world software security initiatives organized so companies can measure their initiatives and understand how to evolve them over time? A. Security features and design B. ISO 27001 C. Building Security in Maturity Model (BSIMM) D. OWASP Software Assurance Maturity Model (SAMM) Correct Answer: C - Building Security in Maturity Model (BSIMM) Explanation: BSIMM is specifically designed to study real-world software security initiatives and help organizations measure and evolve their security practices over time. ________________________________________ 2. What is the analysis of computer software that is performed without executing programs? A. Fuzzing B. Dynamic analysis C. OWASP ZAP D. Static analysis Correct Answer: D - Static analysis Explanation: Static analysis examines source code, bytecode, or binary code without executing the program, identifying potential vulnerabilities through code review and automated tools. ________________________________________ 3. Which secure coding best practice says to use parameterized queries, encrypted connection strings stored in separate configuration files, and strong passwords or multi-factor authentication? A. File management B. Access control C. Session management D. Database security Correct Answer: D - Database security Explanation: These practices specifically relate to protecting database interactions and credentials, which fall under the database security best practice category. ________________________________________ 4. Which secure coding best practice says that all information passed to other systems should be encrypted? A. Output encoding B. Database security C. Communication security D. Memory management Correct Answer: C - Communication security Explanation: Encrypting information passed between systems is a fundamental communication security practice to prevent eavesdropping and data interception. ________________________________________ 5. A company is preparing to add a new feature to its flagship software product. The new feature is similar to features that have been added in previous years, and the requirements are well-documented. The project is expected to last three to four months, at which time the new feature will be released to customers. Project team members will focus solely on the new feature until the project ends. Which software development methodology is being used? A. Scrum B. Extreme programming C. Agile D. Waterfall Correct Answer: D - Waterfall Explanation: The linear, sequential approach with well-documented requirements, fixed timeline, and dedicated team focus until completion characterizes the Waterfall methodology. ________________________________________ 6. A new product will require an administration section for a small number of users. Normal users will be able to view limited customer information and should not see admin functionality within the application. Which concept is being used? A. Software security champion B. Elevation of privilege C. Privacy D. POLP (Principle of Least Privilege) Correct Answer: D - POLP Explanation: The Principle of Least Privilege ensures users only have the minimum access needed for their role, which is demonstrated by restricting admin functionality from normal users. ________________________________________ 7. The software security team is currently working to identify approaches for input validation, authentication, authorization, and configuration management of a new software product so they can deliver a security profile. Which threat modeling step is being described? A. Drawing data flow diagram B. Rating threats C. Analyzing the target D. Identifying and documenting threats Correct Answer: C - Analyzing the target Explanation: Analyzing the target involves identifying security requirements and approaches for various security controls like input validation, authentication, and authorization. ________________________________________ 8. The scrum team is attending their morning meeting, which is scheduled at the beginning of the work day. Each team member reports what they accomplished yesterday, what they plan to accomplish today, and if they have any impediments that may cause them to miss their delivery deadline. Which scrum ceremony is the team participating in? A. Sprint planning B. Sprint review C. Sprint retrospective D. Daily scrum Correct Answer: D - Daily scrum Explanation: The daily scrum (stand-up) is a short daily meeting where team members synchronize activities and report progress, plans, and impediments. ________________________________________ 9. Which security control prevents attackers from injecting malicious code by ensuring that all user input is properly validated before processing? A. Output encoding B. Input validation C. Session management D. Error handling Correct Answer: B - Input validation Explanation: Input validation is the primary defense against injection attacks by checking and sanitizing user-supplied data before it is processed by the application. ________________________________________ 10. What type of testing involves providing invalid, unexpected, or random data as inputs to a computer program?

Content preview

WGU D487 OA EXAM – QUESTIONS COMPLETE WITH
100% VERIFIED CORRECT ANSWERS



1. What is the study of real-world software security initiatives organized so
companies can measure their initiatives and understand how to evolve them
over time?
A. Security features and design
B. ISO 27001
C. Building Security in Maturity Model (BSIMM)
D. OWASP Software Assurance Maturity Model (SAMM)
Correct Answer: C - Building Security in Maturity Model (BSIMM)
Explanation: BSIMM is specifically designed to study real-world software security
initiatives and help organizations measure and evolve their security practices over
time.


2. What is the analysis of computer software that is performed without
executing programs?
A. Fuzzing
B. Dynamic analysis
C. OWASP ZAP
D. Static analysis
Correct Answer: D - Static analysis
Explanation: Static analysis examines source code, bytecode, or binary code
without executing the program, identifying potential vulnerabilities through code
review and automated tools.

,3. Which secure coding best practice says to use parameterized queries,
encrypted connection strings stored in separate configuration files, and strong
passwords or multi-factor authentication?
A. File management
B. Access control
C. Session management
D. Database security
Correct Answer: D - Database security
Explanation: These practices specifically relate to protecting database interactions
and credentials, which fall under the database security best practice category.


4. Which secure coding best practice says that all information passed to other
systems should be encrypted?
A. Output encoding
B. Database security
C. Communication security
D. Memory management
Correct Answer: C - Communication security
Explanation: Encrypting information passed between systems is a fundamental
communication security practice to prevent eavesdropping and data interception.


5. A company is preparing to add a new feature to its flagship software product.
The new feature is similar to features that have been added in previous years,
and the requirements are well-documented. The project is expected to last three
to four months, at which time the new feature will be released to customers.
Project team members will focus solely on the new feature until the project
ends. Which software development methodology is being used?
A. Scrum
B. Extreme programming

,C. Agile
D. Waterfall
Correct Answer: D - Waterfall
Explanation: The linear, sequential approach with well-documented requirements,
fixed timeline, and dedicated team focus until completion characterizes the
Waterfall methodology.


6. A new product will require an administration section for a small number of
users. Normal users will be able to view limited customer information and
should not see admin functionality within the application. Which concept is
being used?
A. Software security champion
B. Elevation of privilege
C. Privacy
D. POLP (Principle of Least Privilege)
Correct Answer: D - POLP
Explanation: The Principle of Least Privilege ensures users only have the minimum
access needed for their role, which is demonstrated by restricting admin
functionality from normal users.


7. The software security team is currently working to identify approaches for
input validation, authentication, authorization, and configuration management
of a new software product so they can deliver a security profile. Which threat
modeling step is being described?
A. Drawing data flow diagram
B. Rating threats
C. Analyzing the target
D. Identifying and documenting threats
Correct Answer: C - Analyzing the target
Explanation: Analyzing the target involves identifying security requirements and

, approaches for various security controls like input validation, authentication, and
authorization.


8. The scrum team is attending their morning meeting, which is scheduled at the
beginning of the work day. Each team member reports what they accomplished
yesterday, what they plan to accomplish today, and if they have any
impediments that may cause them to miss their delivery deadline. Which scrum
ceremony is the team participating in?
A. Sprint planning
B. Sprint review
C. Sprint retrospective
D. Daily scrum
Correct Answer: D - Daily scrum
Explanation: The daily scrum (stand-up) is a short daily meeting where team
members synchronize activities and report progress, plans, and impediments.


9. Which security control prevents attackers from injecting malicious code by
ensuring that all user input is properly validated before processing?
A. Output encoding
B. Input validation
C. Session management
D. Error handling
Correct Answer: B - Input validation
Explanation: Input validation is the primary defense against injection attacks by
checking and sanitizing user-supplied data before it is processed by the
application.


10. What type of testing involves providing invalid, unexpected, or random data
as inputs to a computer program?

Document information

Uploaded on
June 29, 2026
Number of pages
69
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers
$15.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
IszackBd
5.0
(3)
Sold
59
Followers
4
Items
6385
Last sold
1 week ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions