• ¿Documento equivocado? Cámbialo gratis
  • Escrito por estudiantes que aprobaron
  • Inmediatamente disponible después del pago
  • Leer en línea o como PDF
Vender
¿Dónde estudias?
Tu idioma
Document preview thumbnail
Vista previa 3 fuera de 25 páginas
Examen

WGU D385 V2 SOFTWARE SECURITY AND TESTING MASTER QUESTIONS AND ANSWERS

Document preview thumbnail
Vista previa 3 fuera de 25 páginas

WGU D385 V2 SOFTWARE SECURITY AND TESTING MASTER QUESTIONS AND ANSWERS

Vista previa del contenido

WGU D385 V2 SOFTWARE SECURITY
AND TESTING MASTER QUESTIONS
AND ANSWERS




1. Which phase of the Software Development Life Cycle (SDLC) is the most cost-effective for

identifying and addressing security requirements?

A. Maintenance Phase


B. Requirements Analysis Phase


C. Testing Phase


D. Implementation Phase


Answer: B


Conceptual Explanation: Addressing security requirements early in the Requirements

Analysis phase (Shift-Left) prevents costly redesigns during later stages of development.


2. In the context of secure coding, which technique is most effective at preventing SQL

Injection?

A. Blacklisting dangerous characters like single quotes


B. Using client-side JavaScript validation

,C. Encoding output in HTML format


D. Implementing parameterized queries or prepared statements


Answer: D


Conceptual Explanation: Parameterized queries ensure that the database treats user

input as data only, not as executable code, effectively neutralizing SQL injection attacks.


3. What is the primary difference between Static Application Security Testing (SAST) and

Dynamic Application Security Testing (DAST)?

A. SAST is performed during production; DAST is performed during coding.


B. SAST requires the source code; DAST requires a running application.


C. SAST identifies runtime errors; DAST identifies logic flaws in source code.


D. SAST is performed by testers; DAST is performed by developers.


Answer: B


Conceptual Explanation: SAST (White-box) analyzes source code without executing it,

while DAST (Black-box) tests the application while it is running to find vulnerabilities like

session management issues.


4. Which of the following describes a ‘Mutation-Based’ Fuzzing approach?

A. Generating inputs based on a specific protocol or file format definition.


B. Comparing two versions of the same code to find security regressions.


C. Modifying existing valid data inputs to create slightly malformed test cases.

, D. Manually entering edge-case values into form fields.


Answer: C


Conceptual Explanation: Mutation-based fuzzing starts with valid data and applies

random or heuristic changes (mutations) to see how the software handles unexpected

input.


5. Which vulnerability involves an attacker forcing a user’s browser to send a request to a

vulnerable web application where the user is currently authenticated?

A. Cross-Site Request Forgery (CSRF)


B. Insecure Direct Object Reference (IDOR)


C. Cross-Site Scripting (XSS)


D. Server-Side Request Forgery (SSRF)


Answer: A


Conceptual Explanation: CSRF exploits the trust a site has in the user’s browser, tricking

it into performing actions the user did not intend.


6. When implementing OAuth 2.0, which flow is recommended for highly secure server-to-

server communication without a specific user present?

A. Authorization Code Flow


B. Implicit Flow


C. Resource Owner Password Credentials Grant

Información del documento

Subido en
31 de agosto de 2026
Número de páginas
25
Escrito en
2026/2027
Tipo
Examen
Contiene
Preguntas y respuestas
$15.99

¿Documento equivocado? Cámbialo gratis Dentro de los 14 días posteriores a la compra y antes de descargarlo, puedes elegir otro documento. Puedes gastar el importe de nuevo.
Escrito por estudiantes que aprobaron
Inmediatamente disponible después del pago
Leer en línea o como PDF

Seller avatar
Los indicadores de reputación están sujetos a la cantidad de artículos vendidos por una tarifa y las reseñas que ha recibido por esos documentos. Hay tres niveles: Bronce, Plata y Oro. Cuanto mayor reputación, más podrás confiar en la calidad del trabajo del vendedor.
Thebright
3.6
(44)
Vendido
247
Seguidores
6
Artículos
15205
Última venta
1 día hace




Por qué los estudiantes eligen Stuvia

Creado por compañeros estudiantes, verificado por reseñas

Calidad en la que puedes confiar: escrito por estudiantes que aprobaron y evaluado por otros que han usado estos resúmenes.

¿No estás satisfecho? Elige otro documento

¡No te preocupes! Puedes elegir directamente otro documento que se ajuste mejor a lo que buscas.

Paga como quieras, empieza a estudiar al instante

Sin suscripción, sin compromisos. Paga como estés acostumbrado con tarjeta de crédito y descarga tu documento PDF inmediatamente.

Student with book image

“Comprado, descargado y aprobado. Así de fácil puede ser.”

Alisha Student

Preguntas frecuentes