WGU D487 ACTUAL TEST PAPER
ACCURATE QUESTIONS AND CORRECT
ANSWERS GRADED APLUS
●● SDL
Answer: Security Development Lifecycle; security activities integrated
into each SDLC phase so security is built in rather than added at the end.
●● Secure software
Answer: Software that protects confidentiality, integrity, and availability
while meeting its intended function.
●● Software security
Answer: The discipline of preventing, finding, and fixing security
weaknesses in software throughout its life cycle.
●● Security assurance
Answer: Confidence that software security controls and processes are
effective and appropriate for the product's risk.
●● CIA triad
Answer: Confidentiality, integrity, and availability; the three core
security goals.
,●● Confidentiality
Answer: Protecting information from unauthorized disclosure.
●● Integrity
Answer: Protecting data or systems from unauthorized or improper
modification.
●● Availability
Answer: Ensuring systems and data are accessible when needed.
●● Attack surface
Answer: The set of exposed entry points, interfaces, data flows,
privileges, and code paths an attacker could target.
●● Attack surface validation
Answer: Testing and reviewing exposed attack paths to confirm they are
minimized and protected.
●● Threat modeling
Answer: A structured process for identifying assets, attackers, entry
points, threats, vulnerabilities, and mitigations.
,●● Threat
Answer: A potential event or actor that could cause harm to a system or
asset.
●● Vulnerability
Answer: A weakness in software, design, configuration, or process that
can be exploited.
●● Exploit
Answer: A technique, code, or method used to take advantage of a
vulnerability.
●● Attack
Answer: An action taken against a target system; often carried out using
an exploit.
●● Mitigation
Answer: A control or design change that reduces the likelihood or impact
of a threat.
●● Risk
Answer: The combination of likelihood and impact of a threat exploiting
a vulnerability.
, ●● Likelihood
Answer: The probability that a threat will occur or a vulnerability will be
exploited.
●● Impact
Answer: The amount of harm caused if a risk is realized.
●● Risk ranking
Answer: Prioritizing threats or vulnerabilities based on severity,
likelihood, impact, or scoring models.
●● Risk acceptance
Answer: A formal decision to release or continue operating with a
known risk.
●● Security requirement
Answer: A required security behavior, control, or constraint the software
must satisfy.
●● Privacy requirement
Answer: A requirement related to proper collection, use, storage,
disclosure, retention, or deletion of personal data.
ACCURATE QUESTIONS AND CORRECT
ANSWERS GRADED APLUS
●● SDL
Answer: Security Development Lifecycle; security activities integrated
into each SDLC phase so security is built in rather than added at the end.
●● Secure software
Answer: Software that protects confidentiality, integrity, and availability
while meeting its intended function.
●● Software security
Answer: The discipline of preventing, finding, and fixing security
weaknesses in software throughout its life cycle.
●● Security assurance
Answer: Confidence that software security controls and processes are
effective and appropriate for the product's risk.
●● CIA triad
Answer: Confidentiality, integrity, and availability; the three core
security goals.
,●● Confidentiality
Answer: Protecting information from unauthorized disclosure.
●● Integrity
Answer: Protecting data or systems from unauthorized or improper
modification.
●● Availability
Answer: Ensuring systems and data are accessible when needed.
●● Attack surface
Answer: The set of exposed entry points, interfaces, data flows,
privileges, and code paths an attacker could target.
●● Attack surface validation
Answer: Testing and reviewing exposed attack paths to confirm they are
minimized and protected.
●● Threat modeling
Answer: A structured process for identifying assets, attackers, entry
points, threats, vulnerabilities, and mitigations.
,●● Threat
Answer: A potential event or actor that could cause harm to a system or
asset.
●● Vulnerability
Answer: A weakness in software, design, configuration, or process that
can be exploited.
●● Exploit
Answer: A technique, code, or method used to take advantage of a
vulnerability.
●● Attack
Answer: An action taken against a target system; often carried out using
an exploit.
●● Mitigation
Answer: A control or design change that reduces the likelihood or impact
of a threat.
●● Risk
Answer: The combination of likelihood and impact of a threat exploiting
a vulnerability.
, ●● Likelihood
Answer: The probability that a threat will occur or a vulnerability will be
exploited.
●● Impact
Answer: The amount of harm caused if a risk is realized.
●● Risk ranking
Answer: Prioritizing threats or vulnerabilities based on severity,
likelihood, impact, or scoring models.
●● Risk acceptance
Answer: A formal decision to release or continue operating with a
known risk.
●● Security requirement
Answer: A required security behavior, control, or constraint the software
must satisfy.
●● Privacy requirement
Answer: A requirement related to proper collection, use, storage,
disclosure, retention, or deletion of personal data.