WGU - D487 : SECURE SOFTWARE DESIGN QUESTIONS (NEWEST
UPDATED 2025/2026) ACTUAL QUESTIONS AND CORRECT
ANSWERS.
Deployment Phase (SDLC) - ANSWER-Security is pushed out
Design Phase (SDLC) - ANSWER-Requirements are prepared for the technical design
Implementation Phase - ANSWER-The resources involved in the application from a
known resource are determined
Maintenance Phase - ANSWER-Ongoing security monitoring is implemented
Planning Phase of SDLC - ANSWER-vision and next steps are created
secure code - ANSWER-a principle design in coding that refers to code security best
practices, safeguards, and protection against vulnerabilities
threat modeling - ANSWER-a structured process to protect against vulnerabilities
What are the three core elements of security - ANSWER-confidentiality, integrity, and
availability
8 phases of the SDLC - ANSWER-planning, requirements, design, implementation,
testing, deployment, maintenance and end of life
What is software security - ANSWER-Security that deals with securing the foundational
programmatic logic of the underlying software
Which part of the CIA keeps unauthorized users from accessing confidential information
- ANSWER-Confidentiality
BSIMM - ANSWER-a study of real-world software security that allows you to develop
your software security over time
dynamic analysis - ANSWER-analysis of computer software that is performed when
executing the program on a real or virtual processor in real time
fuzz testing - ANSWER-automated or semi-automated testing that provides invalid,
unexpected, or random data to the computer program.
measure model - ANSWER-A set of data security methods that developers take to
protect against vulnerabilities
, metric model - ANSWER-allows organizations to determine the effectiveness of their
security controls
OWASP - ANSWER-A flexible and prospective framework to build security into your
software development organization
static analysis - ANSWER-The analysis of computer software that is performed without
executing programs
Computer Vulnerabilities and Exposures - ANSWER-A list of information that aims to
provide common names for publicly known security vulnerabilities
What are the three primary tools basic to the SDLC - ANSWER-Fuzz testing, static
analysis, and dynamic analysis testing
In which phase of the SDLC should the software security team be involved - ANSWER-
Concept
Waterfall - ANSWER-An approach that divides the process of software development
into separate phases. The outcome of one phase acts as the input for the next phase
Waterfall advantages - ANSWER-Splitting into different stages makes it easier for an
organization to control the development process.
Waterfall Disadvantages - ANSWER-Does not allow time for reflection or a revision to
the design
Agile - ANSWER-Uses collaboration between self-organizing and cross-functional
teams. 4 core values and 12 principles
Agile Advantage - ANSWER-customer satisfaction through rapid, continuous delivery of
useful software
Agile disadvantage - ANSWER-difficult to asses the effort required at the beginning of
the SDL
SCRUM - ANSWER-Development team that works flexibly and holistically to reach a
common goal
Extreme Programming (XP) - ANSWER-Intends to improve software quality and
responsiveness
What determines the order of items in a product backlog in Scrum - ANSWER-Order is
decided based on value of the items being delivered
UPDATED 2025/2026) ACTUAL QUESTIONS AND CORRECT
ANSWERS.
Deployment Phase (SDLC) - ANSWER-Security is pushed out
Design Phase (SDLC) - ANSWER-Requirements are prepared for the technical design
Implementation Phase - ANSWER-The resources involved in the application from a
known resource are determined
Maintenance Phase - ANSWER-Ongoing security monitoring is implemented
Planning Phase of SDLC - ANSWER-vision and next steps are created
secure code - ANSWER-a principle design in coding that refers to code security best
practices, safeguards, and protection against vulnerabilities
threat modeling - ANSWER-a structured process to protect against vulnerabilities
What are the three core elements of security - ANSWER-confidentiality, integrity, and
availability
8 phases of the SDLC - ANSWER-planning, requirements, design, implementation,
testing, deployment, maintenance and end of life
What is software security - ANSWER-Security that deals with securing the foundational
programmatic logic of the underlying software
Which part of the CIA keeps unauthorized users from accessing confidential information
- ANSWER-Confidentiality
BSIMM - ANSWER-a study of real-world software security that allows you to develop
your software security over time
dynamic analysis - ANSWER-analysis of computer software that is performed when
executing the program on a real or virtual processor in real time
fuzz testing - ANSWER-automated or semi-automated testing that provides invalid,
unexpected, or random data to the computer program.
measure model - ANSWER-A set of data security methods that developers take to
protect against vulnerabilities
, metric model - ANSWER-allows organizations to determine the effectiveness of their
security controls
OWASP - ANSWER-A flexible and prospective framework to build security into your
software development organization
static analysis - ANSWER-The analysis of computer software that is performed without
executing programs
Computer Vulnerabilities and Exposures - ANSWER-A list of information that aims to
provide common names for publicly known security vulnerabilities
What are the three primary tools basic to the SDLC - ANSWER-Fuzz testing, static
analysis, and dynamic analysis testing
In which phase of the SDLC should the software security team be involved - ANSWER-
Concept
Waterfall - ANSWER-An approach that divides the process of software development
into separate phases. The outcome of one phase acts as the input for the next phase
Waterfall advantages - ANSWER-Splitting into different stages makes it easier for an
organization to control the development process.
Waterfall Disadvantages - ANSWER-Does not allow time for reflection or a revision to
the design
Agile - ANSWER-Uses collaboration between self-organizing and cross-functional
teams. 4 core values and 12 principles
Agile Advantage - ANSWER-customer satisfaction through rapid, continuous delivery of
useful software
Agile disadvantage - ANSWER-difficult to asses the effort required at the beginning of
the SDL
SCRUM - ANSWER-Development team that works flexibly and holistically to reach a
common goal
Extreme Programming (XP) - ANSWER-Intends to improve software quality and
responsiveness
What determines the order of items in a product backlog in Scrum - ANSWER-Order is
decided based on value of the items being delivered