WGU D488 OA PREP TEST 3 SCRIPT 2026
QUESTIONS AND SOLUTIONS
COMPREHENSIVE STUDY SHEET FULL
PRACTICE SET
◉ What are Security testing reports used for in A5 Ship.
Answer: They document findings from different types of security
testing in this phase of the SDL.
◉ What is the purpose of the Remediation report in A5 Ship.
Answer: To provide the status of the security posture of the product.
◉ What is the Open-source licensing review report used for in A5
Ship?.
Answer: To review compliance with licensing requirements if open-
source software is used.
◉ What do Final security and privacy review reports ensure in A5
Ship?.
Answer: They review compliance with security and privacy
requirements before release.
,◉ What is the purpose of the Customer engagement framework in
A5 Ship?.
Answer: It provides a detailed framework to engage customers
during different stages of the product
◉ What is the purpose of Post-Release Support (PRSA1-5) in SDL?.
Answer: To ensure ongoing security and compliance after product
release, including vulnerability management, third-party reviews,
and legacy system assessments.
◉ What is the External vulnerability disclosure response process in
PRSA?.
Answer: A process to evaluate and communicate security
vulnerabilities found in released products.
◉ What are Post-release certifications in PRSA?.
Answer: Certifications from external parties to demonstrate the
security posture of a product or service.
◉ Why are Third-party security reviews important in PRSA?.
Answer: They involve security assessments performed by
independent groups to ensure objectivity and compliance.
,◉ How does Security strategy for legacy code, M&As, and EOL plans
impact PRSA?.
Answer: It helps mitigate security risks related to older software,
mergers, acquisitions, and end-of-life (EOL) products.
◉ What does PSIRT stand for in the context of software security?.
Answer: Product Security Incident Response Team
◉ What is the role of a PSIRT in post-release security?.
Answer: A PSIRT is responsible for responding to software product
security incidents involving external discoveries of post-release
software security vulnerabilities.
◉ Who are potential external discoverers of software
vulnerabilities?.
Answer: Independent security researchers
Consultants
Industry organizations
Other vendors
Benevolent or malicious hackers
◉ How does PSIRT prioritize identified security issues?.
Answer: Based on the potential severity of the vulnerability
, Typically using the CVSS scoring system
Considering other environmental factors
◉ What does the CVSS model measure in vulnerability assessment?.
Answer: It uses base, temporal, and environmental calculations to
determine the severity of a security vulnerability.
◉ What are the four severity levels in CVSS scoring?.
Answer: Critical (C) - CVSS base score of 9.0-10.0
High (H) - CVSS base score of 7.0-8.9
Medium (M) - CVSS base score of 4.0-6.9
Low (L) - CVSS base score of 0.1-3.9
◉ What does PSIRT use CVSS scoring for?.
Answer: To prioritize responses to externally discovered
vulnerabilities
To determine the severity of security incidents
To modify scores based on factors not captured in the standard CVSS
model
◉ When does a PSIRT typically make a public disclosure about a
security vulnerability?.
QUESTIONS AND SOLUTIONS
COMPREHENSIVE STUDY SHEET FULL
PRACTICE SET
◉ What are Security testing reports used for in A5 Ship.
Answer: They document findings from different types of security
testing in this phase of the SDL.
◉ What is the purpose of the Remediation report in A5 Ship.
Answer: To provide the status of the security posture of the product.
◉ What is the Open-source licensing review report used for in A5
Ship?.
Answer: To review compliance with licensing requirements if open-
source software is used.
◉ What do Final security and privacy review reports ensure in A5
Ship?.
Answer: They review compliance with security and privacy
requirements before release.
,◉ What is the purpose of the Customer engagement framework in
A5 Ship?.
Answer: It provides a detailed framework to engage customers
during different stages of the product
◉ What is the purpose of Post-Release Support (PRSA1-5) in SDL?.
Answer: To ensure ongoing security and compliance after product
release, including vulnerability management, third-party reviews,
and legacy system assessments.
◉ What is the External vulnerability disclosure response process in
PRSA?.
Answer: A process to evaluate and communicate security
vulnerabilities found in released products.
◉ What are Post-release certifications in PRSA?.
Answer: Certifications from external parties to demonstrate the
security posture of a product or service.
◉ Why are Third-party security reviews important in PRSA?.
Answer: They involve security assessments performed by
independent groups to ensure objectivity and compliance.
,◉ How does Security strategy for legacy code, M&As, and EOL plans
impact PRSA?.
Answer: It helps mitigate security risks related to older software,
mergers, acquisitions, and end-of-life (EOL) products.
◉ What does PSIRT stand for in the context of software security?.
Answer: Product Security Incident Response Team
◉ What is the role of a PSIRT in post-release security?.
Answer: A PSIRT is responsible for responding to software product
security incidents involving external discoveries of post-release
software security vulnerabilities.
◉ Who are potential external discoverers of software
vulnerabilities?.
Answer: Independent security researchers
Consultants
Industry organizations
Other vendors
Benevolent or malicious hackers
◉ How does PSIRT prioritize identified security issues?.
Answer: Based on the potential severity of the vulnerability
, Typically using the CVSS scoring system
Considering other environmental factors
◉ What does the CVSS model measure in vulnerability assessment?.
Answer: It uses base, temporal, and environmental calculations to
determine the severity of a security vulnerability.
◉ What are the four severity levels in CVSS scoring?.
Answer: Critical (C) - CVSS base score of 9.0-10.0
High (H) - CVSS base score of 7.0-8.9
Medium (M) - CVSS base score of 4.0-6.9
Low (L) - CVSS base score of 0.1-3.9
◉ What does PSIRT use CVSS scoring for?.
Answer: To prioritize responses to externally discovered
vulnerabilities
To determine the severity of security incidents
To modify scores based on factors not captured in the standard CVSS
model
◉ When does a PSIRT typically make a public disclosure about a
security vulnerability?.