1|Page
WGU D487 SECURE SOFTWARE DESIGN
OBJECTIVE ASSESSMENT ACTUAL EXAM PREP
2026 ALL QUESTIONS AND CORRECT
DETAILED ANSWERS WITH RATIONALES
ALREADY A GRADED WITH EXPERT
FEEDBACK |NEW AND REVISED
1. What is the primary goal of secure software design?
A. Maximize software performance and efficiency
B. Protect applications from security threats throughout the SDLC
C. Reduce overall development time and costs
D. Enhance the user interface and experience
Rationale: Secure software design focuses on mitigating
vulnerabilities throughout the software development lifecycle (SDLC).
While performance, cost, and user experience are important
considerations, the primary goal is to protect applications from
security threats.
2. Which SDLC phase is most critical for integrating security?
A. Testing
B. Requirements gathering
C. Deployment
D. Maintenance
Rationale: Early integration of security in the requirements gathering
phase ensures security is built into the application from the beginning,
,2|Page
following NIST guidelines. Addressing security late in the SDLC is
more costly and less effective.
3. What is the purpose of threat modeling in secure software design?
A. Optimize code execution efficiency
B. Identify potential security risks and vulnerabilities
C. Increase system uptime and availability
D. Reduce hardware and infrastructure costs
Rationale: Threat modeling is a structured process to systematically
identify, quantify, and address security risks associated with an
application by analyzing its architecture, data flows, and potential
threats.
4. What does the STRIDE threat modeling acronym stand for?
A. Spoofing, Tampering, Repudiation, Information Disclosure,
Denial of Service, Elevation of Privilege
B. Spoofing, Tracking, Repudiation, Injection, Disclosure, Execution
C. Scanning, Tampering, Repudiation, Injection, Disclosure,
Exploitation
D. Spoofing, Tampering, Replay, Information Disclosure, DoS,
Escalation
Rationale: STRIDE is a Microsoft threat categorization framework
where each letter represents a threat category: Spoofing, Tampering,
Repudiation, Information Disclosure, Denial of Service, and Elevation
of Privilege.
5. Which principle mandates that users should be granted the minimum
level of access necessary to perform their job functions?
,3|Page
A. Least Privilege
B. Defense in Depth
C. Separation of Duties
D. Complete Mediation
Rationale: The Principle of Least Privilege (PoLP) mandates that any
user, process, or system should be granted the minimum levels of
access necessary to perform its authorized functions, limiting potential
damage from accidents or attacks.
6. Which security design principle advocates for multiple, layered
security controls so that if one layer fails, others remain to protect the
asset?
A. Least Privilege
B. Fail-Safe Defaults
C. Defense in Depth
D. Economy of Mechanism
Rationale: Defense in Depth employs multiple, layered security
controls (physical, network, host, application, data) so that if one layer
fails, others remain to protect the asset.
7. In the STRIDE model, which threat involves pretending to be
someone or something else?
A. Spoofing
B. Tampering
C. Repudiation
D. Elevation of Privilege
Rationale: Spoofing is the act of pretending to be someone or
something else, such as stealing a session cookie or forging an
identity. It violates the security property of authentication.
, 4|Page
8. What is the key idea behind Fail-Safe Defaults?
A. Systems should default to allowing all access
B. Access decisions should default to "deny" unless explicitly
permitted
C. Systems should continue operating during failures
D. Security controls should be optional
Rationale: Fail-Safe Defaults means that access decisions should
default to "deny" unless explicitly permitted. The system should
remain secure in the event of a failure.
9. Which risk assessment model is used to prioritize found threats based
on Damage, Reproducibility, Exploitability, Affected Users, and
Discoverability?
A. STRIDE
B. DREAD
C. PASTA
D. OCTAVE
Rationale: DREAD is a risk rating model used for quantitatively
prioritizing found threats based on five factors: Damage,
Reproducibility, Exploitability, Affected Users, and Discoverability.
10. What does the CIA Triad represent in information security?
A. Confidentiality, Integrity, Availability
B. Confidentiality, Identity, Accountability
C. Confidentiality, Integrity, Availability
D. Control, Identity, Authentication
WGU D487 SECURE SOFTWARE DESIGN
OBJECTIVE ASSESSMENT ACTUAL EXAM PREP
2026 ALL QUESTIONS AND CORRECT
DETAILED ANSWERS WITH RATIONALES
ALREADY A GRADED WITH EXPERT
FEEDBACK |NEW AND REVISED
1. What is the primary goal of secure software design?
A. Maximize software performance and efficiency
B. Protect applications from security threats throughout the SDLC
C. Reduce overall development time and costs
D. Enhance the user interface and experience
Rationale: Secure software design focuses on mitigating
vulnerabilities throughout the software development lifecycle (SDLC).
While performance, cost, and user experience are important
considerations, the primary goal is to protect applications from
security threats.
2. Which SDLC phase is most critical for integrating security?
A. Testing
B. Requirements gathering
C. Deployment
D. Maintenance
Rationale: Early integration of security in the requirements gathering
phase ensures security is built into the application from the beginning,
,2|Page
following NIST guidelines. Addressing security late in the SDLC is
more costly and less effective.
3. What is the purpose of threat modeling in secure software design?
A. Optimize code execution efficiency
B. Identify potential security risks and vulnerabilities
C. Increase system uptime and availability
D. Reduce hardware and infrastructure costs
Rationale: Threat modeling is a structured process to systematically
identify, quantify, and address security risks associated with an
application by analyzing its architecture, data flows, and potential
threats.
4. What does the STRIDE threat modeling acronym stand for?
A. Spoofing, Tampering, Repudiation, Information Disclosure,
Denial of Service, Elevation of Privilege
B. Spoofing, Tracking, Repudiation, Injection, Disclosure, Execution
C. Scanning, Tampering, Repudiation, Injection, Disclosure,
Exploitation
D. Spoofing, Tampering, Replay, Information Disclosure, DoS,
Escalation
Rationale: STRIDE is a Microsoft threat categorization framework
where each letter represents a threat category: Spoofing, Tampering,
Repudiation, Information Disclosure, Denial of Service, and Elevation
of Privilege.
5. Which principle mandates that users should be granted the minimum
level of access necessary to perform their job functions?
,3|Page
A. Least Privilege
B. Defense in Depth
C. Separation of Duties
D. Complete Mediation
Rationale: The Principle of Least Privilege (PoLP) mandates that any
user, process, or system should be granted the minimum levels of
access necessary to perform its authorized functions, limiting potential
damage from accidents or attacks.
6. Which security design principle advocates for multiple, layered
security controls so that if one layer fails, others remain to protect the
asset?
A. Least Privilege
B. Fail-Safe Defaults
C. Defense in Depth
D. Economy of Mechanism
Rationale: Defense in Depth employs multiple, layered security
controls (physical, network, host, application, data) so that if one layer
fails, others remain to protect the asset.
7. In the STRIDE model, which threat involves pretending to be
someone or something else?
A. Spoofing
B. Tampering
C. Repudiation
D. Elevation of Privilege
Rationale: Spoofing is the act of pretending to be someone or
something else, such as stealing a session cookie or forging an
identity. It violates the security property of authentication.
, 4|Page
8. What is the key idea behind Fail-Safe Defaults?
A. Systems should default to allowing all access
B. Access decisions should default to "deny" unless explicitly
permitted
C. Systems should continue operating during failures
D. Security controls should be optional
Rationale: Fail-Safe Defaults means that access decisions should
default to "deny" unless explicitly permitted. The system should
remain secure in the event of a failure.
9. Which risk assessment model is used to prioritize found threats based
on Damage, Reproducibility, Exploitability, Affected Users, and
Discoverability?
A. STRIDE
B. DREAD
C. PASTA
D. OCTAVE
Rationale: DREAD is a risk rating model used for quantitatively
prioritizing found threats based on five factors: Damage,
Reproducibility, Exploitability, Affected Users, and Discoverability.
10. What does the CIA Triad represent in information security?
A. Confidentiality, Integrity, Availability
B. Confidentiality, Identity, Accountability
C. Confidentiality, Integrity, Availability
D. Control, Identity, Authentication