OBJECTIVE ASSESSMENT TEST BANK V1
150 Questions and Correct Verified Answers
Aligned with 2026-2027 Standards
Western Governors University | Cybersecurity Program
100% Correct Answers with Comprehensive Rationales
Seven Sections | Multiple Choice (A-D) | Scenario-Based and Recall
TEST BANK V1 - UNIQUE QUESTIONS
,WGU D487 Secure Software Design | Test Bank V1 | 2026-2027 150 Questions with Verified Answers
WGU D487 SECURE SOFTWARE DESIGN
Objective Assessment Test Bank V1 | 2026-2027
Exam Type WGU D487 Objective Assessment (OA)
Total Questions 150 Multiple Choice (A-D)
Passing Requirement 70% minimum per section (WGU standard)
Content Coverage 7 Sections covering all D487 course competencies and OA blueprint
Question Types 75% scenario-based, 25% direct recall/terminology
OWASP Top 10 (2021), NIST CSF, ISO 27034, CWE/SANS Top 25, PCI DSS, HIPAA,
Key References
GDPR
Exam Content Sections
Section 1: Foundational Security Concepts and Design Principles
CIA Triad, IAAA, Defense-in-Depth, Least Privilege, Attack Surface, Zero Trust, Q1-Q25 25 Q
Saltzer-Schroeder Principles
Section 2: Threat Modeling and Risk Assessment
Q26-Q45 20 Q
STRIDE, DREAD, Attack Trees, PASTA, OCTAVE, Risk Analysis Frameworks
Section 3: OWASP Top 10 Vulnerabilities and Mitigations
Injection, XSS, CSRF, SSRF, IDOR, Broken Authentication, Cryptographic Failures, Q46-Q70 25 Q
Security Misconfigurations, Insecure Design, Logging/Monitoring
Section 4: Security Controls and Implementation
Access Control Models, Session Management, Cryptography, Input Validation, Q71-Q95 25 Q
Output Encoding
Section 5: Secure SDLC and DevSecOps Integration
SDLC Models, Security Requirements, CI/CD Pipeline Security, Infrastructure as Q96-Q115 20 Q
Code, Shift-Left Security
Section 6: Application Security Testing
SAST, DAST, IAST, RASP, SCA, Penetration Testing, Vulnerability Management Q116-Q135 20 Q
Lifecycle
Section 7: Secure Architecture, Compliance, and Advanced Topics
Security Patterns, Microservices, API Security, NIST, ISO 27034, OWASP ASVS, Q136-Q150 15 Q
PCI DSS, HIPAA, GDPR, SBOM, Supply Chain, AI/ML Security
Page 1
,WGU D487 Secure Software Design | Test Bank V1 | 2026-2027 150 Questions with Verified Answers
Section 1: Foundational Security Concepts and Design Principles
CIA Triad, IAAA, Defense-in-Depth, Least Privilege, Attack Surface, Zero Trust, Saltzer-Schroeder Principles
Q1: A software architect is designing a healthcare application that must ensure patient records are accessible only to
authorized medical staff. Which CIA triad component is the PRIMARY focus of this requirement?
A. Integrity
B. Availability
C. Confidentiality [CORRECT]
D. Non-repudiation
Correct Answer: C
Rationale: Confidentiality ensures that data is accessible only to authorized individuals, which directly addresses the requirement to restrict patient
record access to authorized medical staff. Integrity protects against unauthorized data modification, not unauthorized access. Availability ensures
timely access but does not control who can access data. Non-repudiation provides proof of origin and delivery, which is an IAAA concept, not a CIA
component.
Q2: An e-commerce platform discovers that an attacker modified product prices during transmission from the
server to the client. Which CIA triad principle was violated?
A. Confidentiality
B. Integrity [CORRECT]
C. Availability
D. Authentication
Correct Answer: B
Rationale: Integrity ensures that data is not altered in unauthorized ways during storage or transmission. Modifying prices during transmission is a
classic integrity violation. Confidentiality deals with unauthorized disclosure, not modification. Availability deals with ensuring systems and data are
accessible. Authentication is an IAAA component used to verify identity, not a CIA triad principle.
Q3: A DDoS attack overwhelms a bank's online banking service, preventing legitimate customers from accessing
their accounts. Which CIA triad component is primarily affected?
A. Confidentiality
B. Integrity
C. Availability [CORRECT]
D. Accountability
Correct Answer: C
Rationale: Availability ensures that systems and data are accessible to authorized users when needed. A DDoS attack that prevents legitimate access
directly violates availability. Confidentiality and integrity are not the primary concern in this scenario since the data is not disclosed or modified.
Accountability is an IAAA principle, not part of the CIA triad.
Page 2
, WGU D487 Secure Software Design | Test Bank V1 | 2026-2027 150 Questions with Verified Answers
Q4: In a secure software design review, a security engineer argues that implementing strong encryption for all data
at rest will inherently reduce system performance, creating a trade-off with which CIA component?
A. Confidentiality vs. Availability [CORRECT]
B. Integrity vs. Confidentiality
C. Availability vs. Integrity
D. Confidentiality vs. Non-repudiation
Correct Answer: A
Rationale: Strong encryption enhances confidentiality but adds computational overhead that can impact system responsiveness and throughput,
creating a trade-off with availability. This is a classic security design tension where maximizing one CIA component may reduce another. Integrity is
about data accuracy, not performance. Non-repudiation is not a CIA triad component. The WGU D487 course emphasizes understanding these
interdependencies.
Q5: Which IAAA component is responsible for establishing and verifying the identity of a user or system?
A. Authorization
B. Authentication [CORRECT]
C. Accountability
D. Identification
Correct Answer: B
Rationale: Authentication is the process of verifying that a claimed identity is genuine, typically through passwords, biometrics, tokens, or
multi-factor methods. Identification is merely claiming an identity (e.g., entering a username). Authorization determines what an authenticated user
can do. Accountability ensures actions can be traced to specific entities. The WGU D487 course distinguishes between identification (who you claim
to be) and authentication (proving who you are).
Q6: A web application uses role-based access control to determine which features each user can access after login.
Which IAAA component does this represent?
A. Identification
B. Authentication
C. Authorization [CORRECT]
D. Accountability
Correct Answer: C
Rationale: Authorization is the process of determining what actions an authenticated identity is permitted to perform. RBAC is a common
authorization mechanism that assigns permissions based on user roles. Identification establishes who the user claims to be, authentication verifies that
claim, and accountability tracks user actions for audit purposes. In the WGU D487 framework, authorization always follows successful
authentication.
Q7: An application generates detailed audit logs that record every user action with a timestamp and user ID. Which
IAAA component does this support?
A. Identification
B. Authentication
C. Authorization
D. Accountability [CORRECT]
Correct Answer: D
Rationale: Accountability ensures that every action can be traced back to a specific entity, which is achieved through comprehensive audit logging
with timestamps and user identifiers. This supports forensic analysis, compliance requirements, and deterrence against misuse. Identification,
authentication, and authorization are prerequisite steps but do not themselves provide the traceability that accountability requires.
Page 3