• Wrong document? Swap it for free
  • Written by students who passed
  • Immediately available after payment
  • Read online or as PDF
Sell
Where do you study
Your language
Document preview thumbnail
Preview 3 out of 25 pages
Exam (elaborations)

WGU D385 V2 SOFTWARE SECURITY AND TESTING MASTER FINAL EXAM QUESTIONS AND ANSWERS

Document preview thumbnail
Preview 3 out of 25 pages

WGU D385 V2 SOFTWARE SECURITY AND TESTING MASTER FINAL EXAM QUESTIONS AND ANSWERS

Content preview

WGU D385 V2 SOFTWARE SECURITY
AND TESTING MASTER FINAL EXAM
QUESTIONS AND ANSWERS




1. Which of the following describes a vulnerability where an attacker manipulates the

internal logic of a web application to access unauthorized data records by changing a unique

identifier?

A. Cross-Site Request Forgery (CSRF)


B. Cross-Site Scripting (XSS)


C. Server-Side Request Forgery (SSRF)


D. Insecure Direct Object Reference (IDOR)


Answer: D


Conceptual Explanation: IDOR occurs when an application provides direct access to

objects based on user-supplied input, allowing attackers to bypass authorization by

changing IDs in URLs or parameters.

,2. In the context of secure software development, what is the primary purpose of ‘Input

Validation’?

A. To ensure data is formatted correctly for display in the UI


B. To improve the performance of database queries


C. To compress data before it is stored in the cloud


D. To ensure that only properly formed data enters the system workflow


Answer: D


Conceptual Explanation: Input validation is a core security control that ensures data

received by an application matches expected formats, types, and lengths, preventing

malicious data from triggering vulnerabilities.


3. Which testing methodology involves analyzing the source code without executing the

program?

A. Dynamic Application Security Testing (DAST)


B. Fuzz Testing


C. Regression Testing


D. Static Application Security Testing (SAST)


Answer: D


Conceptual Explanation: SAST (Static Analysis) examines source code, byte code, or

binaries for security vulnerabilities without running the code.

, 4. What is the most effective way to prevent SQL Injection vulnerabilities in a modern web

application?

A. Using client-side JavaScript filters


B. Implementing Web Application Firewalls (WAF) exclusively


C. Encoding all output in HTML entities


D. Using parameterized queries or prepared statements


Answer: D


Conceptual Explanation: Parameterized queries ensure that the database treats user

input as data rather than executable code, neutralizing SQL injection attempts.


5. A developer is implementing a logging system. Which of the following should be EXCLUDED

from logs to ensure security and compliance?

A. Session IDs and full credit card numbers


B. Timestamp of the event


C. The User-Agent string of the browser


D. Error codes returned by the server


Answer: A


Conceptual Explanation: Sensitive Personal Identifiable Information (PII) and credentials

like session IDs or credit card numbers should never be logged to prevent data exposure in

case of a log breach.

Document information

Uploaded on
August 31, 2026
Number of pages
25
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$15.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
Thebright
3.6
(44)
Sold
247
Followers
6
Items
15205
Last sold
1 day ago




Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions