Secure Software Design Objective Assessment (OA) |
Latest 2025–2026 Practice Questions & Verified Answers |
Comprehensive Study Guide
THIS STUDY GUIDE INCLUDES:
• ✅ WGU D487 Objective Assessment (OA) practice questions
• ✅ Verified questions and answers
• ✅ Detailed answer explanations
• ✅ Secure Software Design fundamentals
• ✅ Secure Software Development Lifecycle (SSDLC)
• ✅ Scenario-based practice questions
• ✅ Comprehensive exam review
• ✅ Printable PDF format
• ✅ Latest 2025–2026 updated study material
, WGU D487 Secure Software Design Objective
Assessment (OA) | Latest 2025–2026 Practice
Questions & Verified Answers | Comprehensive
Study Guide
Question 1
Question: What are the two common best principles of software
applications in the development process? (Choose 2 answers)
A) Integrity and Availability
B) Quality code and Secure code
C) Information security and Reliability
D) Authentication and Authorization
Answer: B) Quality code and Secure code
Explanation:
• Quality code is efficient code that is easy to maintain and
reusable. It follows best practices, is well-documented, and
reduces technical debt.
• Secure code authorizes and authenticates every user
transaction, logs the transaction, and denies all unauthorized
, requisitions. Secure code ensures that the application is
protected against common vulnerabilities and attacks.
• The other options (Integrity, Availability, Information
security, Reliability, Authentication, Authorization) are
important security concepts but do not represent the two
primary principles of software application development.
Question 2
Question: What ensures that the user has the appropriate role
and privilege to view data?
A) Authentication
B) Multi-factor authentication
C) Encryption
D) Authorization
Answer: D) Authorization
Explanation: Authorization ensures a user's information and
credentials are approved by the system. While authentication
verifies the identity of a user (who they are), authorization
determines what resources and actions that authenticated user is
permitted to access (what they can do). Authorization is typically
, implemented through role-based access control (RBAC), access
control lists (ACLs), or attribute-based access control (ABAC).
Question 3
Question: Which security goal is defined by "guarding against
improper information modification or destruction and ensuring
information non-repudiation and authenticity"?
A) Integrity
B) Quality
C) Availability
D) Reliability
Answer: A) Integrity
Explanation: Integrity is one of the three pillars of the CIA triad
(Confidentiality, Integrity, Availability). It ensures that data
remains unchanged by unauthorized users and remains reliable
from the data entry point to the database and back. Integrity
includes:
• Non-repudiation: Ensuring that a party cannot deny having
performed a particular action