• Wrong document? Swap it for free
  • Written by students who passed
  • Immediately available after payment
  • Read online or as PDF
Sell
Where do you study
Your language
Document preview thumbnail
Preview 4 out of 126 pages
Exam (elaborations)

WGU D487 Secure Software Design Test Bank 3 420 Questions Actual Exam 2026/2027 – 100% Verified | Detailed Rationales – Pass Guaranteed – A+ Graded

Document preview thumbnail
Preview 4 out of 126 pages

WGU D487 Secure Software Design Test Bank 3 420 Questions Actual Exam 2026/2027 – 100% Correct Answers | Real-Style Questions with Answers | Security Architecture, Threat Modeling, Secure Coding, Cryptography, Access Control | Graded A+ Verified | Risk Management, Vulnerability Assessment, Compliance, SDLC Security | Detailed Rationales | Verified Correct Answers – Pass Guaranteed – Instant Download

Content preview

WGU D487 Secure Software Design



OBJECTIVE ASSESSMENT - EXAM


WGU D487 Oa 2026/2027 Test Bank 3
With 420 Questions And Correct Answers (100% Correct Verified Answers)
D487 Secure Software Design Objective Assessment 2026/2027 Test Bank V3




Comprehensive examination covering secure software design principles, threat modeling
and risk assessment, secure coding practices, authentication and authorization,
cryptography and data protection, security architecture and patterns, vulnerability
assessment and testing, and DevSecOps and compliance for the WGU cybersecurity
program.




A+ 2026/2027 75% 8
Verified EDITION PASSING
SCORE Sections
QUALITY COVERAGE
STATUS




WGU D487 Oa 2026/2027 Test Bank 3 With 420 Questions And Correct Answers (100% Correct Verified Answers) D487 Secure Software Design Objective Assessment COVER PAGE
2026/2027 Test Bank V3 2026/2027 -1

,SECTIONS COVERED

Section 1: Secure Software Design Principles (Questions 1-50)
Section 2: Threat Modeling & Risk Assessment (Questions 51-100)
Section 3: Secure Coding Practices (Questions 101-150)
Section 4: Authentication & Authorization (Questions 151-200)
Section 5: Cryptography & Data Protection (Questions 201-250)
Section 6: Security Architecture & Patterns (Questions 251-300)
Section 7: Vulnerability Assessment & Testing (Questions 301-350)
Section 8: DevSecOps & Compliance (Questions 351-400)


This examination is designed for WGU D487 Secure Software Design Objective Assessment candidates. It
evaluates competency in secure design principles, threat modeling, secure coding, authentication and
authorization, cryptography, security architecture, vulnerability assessment, and DevSecOps. Each question
requires analysis and evaluation at the Bloom's taxonomy levels of Analysis and Evaluation. A passing score of
75% is required. Select the single best answer for each question.




Section 1: Secure Software Design Principles

Q1
A hospital information system allows nurses to view patient records but also grants them access to the billing
modification module. A security audit reveals that nurses have never needed to modify billing records. The design
team is reviewing access policies to align with foundational security principles. What principle is most directly
violated by the current access configuration?
A. Defense in depth
B. Principle of least privilege
C. Economy of mechanism
D. Open design principle
Correct Answer: B
Rationale: The principle of least privilege states that subjects should only be granted the minimum access necessary to
perform their tasks. Nurses who never modify billing records should not have access to the billing modification module,
making this a clear violation of least privilege.


Q2
An e-commerce platform relies solely on a perimeter firewall to protect its web application from attacks. After a
recent breach, the security architect recommends adding a web application firewall, input validation at the
application layer, and encrypted database connections. This layered approach exemplifies a core security design
principle. Which principle is being applied?
A. Defense in depth
B. Fail-safe defaults
C. Least common mechanism
D. Psychological acceptability
Correct Answer: A
Rationale: Defense in depth is the strategy of using multiple overlapping security controls so that if one layer fails,
additional layers continue to provide protection. Adding a WAF, input validation, and encryption alongside the perimeter

, firewall implements this layered approach.


Q3
A newly developed access control module returns an error when it cannot reach the directory server to verify user
permissions. The system currently grants access during this failure condition so that users are not locked out. The
security team insists this behavior must be changed. Which design principle requires that the system deny access
when the permission check fails?
A. Principle of least privilege
B. Complete mediation
C. Fail-safe defaults
D. Separation of privilege
Correct Answer: C
Rationale: Fail-safe defaults dictates that the default access decision must be denial when a system cannot determine the
correct permission. Granting access during a failure condition violates this principle because the safe default is to restrict
access until authorization can be confirmed.


Q4
A security team is designing an authentication system and must choose between a custom-built cryptographic
protocol with twelve interdependent steps and a well-vetted implementation using standard TLS with three clear
steps. The team lead advocates for the simpler design to reduce the chance of implementation errors. Which
principle supports this decision?
A. Economy of mechanism
B. Defense in breadth
C. Least common mechanism
D. Psychological acceptability
Correct Answer: A
Rationale: Economy of mechanism favors simpler designs over complex ones because simpler designs are easier to
verify, test, and maintain with fewer opportunities for flaws. Choosing the three-step TLS implementation over the
twelve-step custom protocol directly reflects this principle.


Q5
A file server checks user permissions at the start of a session and then allows all subsequent file reads and writes
without rechecking authority. A user whose role is downgraded mid-session can still write to restricted files until the
session ends. Which principle is being violated?
A. Open design principle
B. Complete mediation
C. Separation of privilege
D. Economy of mechanism
Correct Answer: B
Rationale: Complete mediation requires that every access to an object be checked for authorization, not just the first
access. Failing to recheck permissions after a role change violates this principle because the system assumes prior
authorization remains valid indefinitely.


Q6
A development team insists that the security of their proprietary encryption algorithm depends on keeping the
algorithm secret and refuses to allow external review. Security experts argue that the algorithm should be
published for public scrutiny while relying only on the secrecy of the key. Which principle states that security should
not depend on the secrecy of the design?
A. Principle of least privilege


WGU D487 Secure Software Design OA 2026/2027 | Page 2

, B. Fail-safe defaults
C. Open design principle
D. Least common mechanism
Correct Answer: C
Rationale: The open design principle, also known as Kerckhoffs's principle, holds that the security of a system should not
depend on keeping its algorithms or mechanisms secret, only on keeping keys secret. Public scrutiny of the design
increases confidence in its security.


Q7
A financial application requires a single administrator password to both approve large transactions and modify
system configuration settings. After an incident where a compromised admin account was used to do both, the
security team recommends splitting these duties so that two separate credentials are required. Which principle
does this recommendation reflect?
A. Separation of privilege
B. Least common mechanism
C. Psychological acceptability
D. Defense in breadth
Correct Answer: A
Rationale: Separation of privilege requires that access to critical functions depend on multiple conditions or parties rather
than a single privilege. Splitting transaction approval and configuration modification into separate credentials ensures that
compromising one account cannot perform both actions.


Q8
Two independently governed departments share a single communication channel that processes messages for
both. A vulnerability in the shared channel exposes data from both departments simultaneously. The security
architect recommends implementing separate channels for each department. Which principle motivates this
recommendation?
A. Complete mediation
B. Separation of privilege
C. Economy of mechanism
D. Least common mechanism
Correct Answer: D
Rationale: The least common mechanism principle states that mechanisms used by different users or processes should
be minimized to reduce the shared attack surface. Separate communication channels eliminate the shared vulnerability
pathway that could compromise both departments.


Q9
A company implements a new authentication system that requires employees to enter a 30-character password
with six special character types, change it weekly, and prohibits password managers. Within a month, help desk
reports show widespread use of passwords written on sticky notes. The security team needs to redesign the policy.
Which principle was most neglected?
A. Defense in depth
B. Psychological acceptability
C. Economy of mechanism
D. Open design principle
Correct Answer: B
Rationale: Psychological acceptability requires that security mechanisms be designed to be as easy to use as possible so
that users will routinely comply rather than seek workarounds. Excessively complex password requirements that drive
users to write passwords on sticky notes directly violate this principle.




WGU D487 Secure Software Design OA 2026/2027 | Page 3

Document information

Uploaded on
August 7, 2026
Number of pages
126
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$17.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
STUVIAACTUALEXAMS
3.5
(179)
Sold
1349
Followers
209
Items
10317
Last sold
15 hours ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions