1|Page
WGU D487 SECURE SW DESIGN EXAM 2026 ACTUAL EXAM 2
VERSIONS (VERSION A AND B) COMPLETE ACCURATE EXAM
QUESTIONS WITH DETAILED VERIFIED ANSWERS (100%
CORRECT ANSWERS) /ALREADY GRADED A+
1. A development team is designing a financial application and wants
security considerations to influence requirements, architecture,
implementation, testing, deployment, and maintenance rather than
being addressed only after coding is complete. Which approach BEST
reflects secure software design?
A. Add penetration testing immediately before release
B. Integrate security activities throughout the software development
lifecycle
C. Perform security reviews only after production deployment
D. Delegate all security decisions to the operations team
Answer: B
2. A service account is given access only to the databases, files, and
functions required for its assigned task. Which secure design principle is
being applied?
A. Fail-safe defaults
B. Defense in depth
,2|Page
C. Least privilege
D. Complete mediation
Answer: C
3. An application uses multiple independent security controls so that
failure of one control does not automatically expose sensitive
information. Which principle does this BEST demonstrate?
A. Defense in depth
B. Open design
C. Economy of mechanism
D. Separation of duties
Answer: A
4. A system rejects an access request whenever authorization
information is unavailable instead of granting access automatically.
Which principle is MOST directly demonstrated?
A. Least common mechanism
B. Fail securely
C. Open design
,3|Page
D. Psychological acceptability
Answer: B
5. A development team creates a data-flow diagram showing external
entities, processes, data stores, and communication paths before
implementing a new application. What security activity is this MOST
useful for?
A. Threat modeling
B. Performance benchmarking
C. User acceptance testing
D. Capacity planning
Answer: A
6. During threat modeling, a team identifies an attacker who could
impersonate a legitimate user and gain unauthorized access to an
account. Which STRIDE category BEST represents this threat?
A. Tampering
B. Repudiation
C. Spoofing
, 4|Page
D. Information disclosure
Answer: C
7. An attacker modifies transaction data while it is being processed,
causing an incorrect payment amount to be recorded. Which STRIDE
category BEST describes this threat?
A. Tampering
B. Spoofing
C. Repudiation
D. Denial of service
Answer: A
8. A user performs an unauthorized transaction and later claims that
the transaction never occurred. Which security concern is MOST
directly involved?
A. Spoofing
B. Repudiation
C. Elevation of privilege
D. Information disclosure
WGU D487 SECURE SW DESIGN EXAM 2026 ACTUAL EXAM 2
VERSIONS (VERSION A AND B) COMPLETE ACCURATE EXAM
QUESTIONS WITH DETAILED VERIFIED ANSWERS (100%
CORRECT ANSWERS) /ALREADY GRADED A+
1. A development team is designing a financial application and wants
security considerations to influence requirements, architecture,
implementation, testing, deployment, and maintenance rather than
being addressed only after coding is complete. Which approach BEST
reflects secure software design?
A. Add penetration testing immediately before release
B. Integrate security activities throughout the software development
lifecycle
C. Perform security reviews only after production deployment
D. Delegate all security decisions to the operations team
Answer: B
2. A service account is given access only to the databases, files, and
functions required for its assigned task. Which secure design principle is
being applied?
A. Fail-safe defaults
B. Defense in depth
,2|Page
C. Least privilege
D. Complete mediation
Answer: C
3. An application uses multiple independent security controls so that
failure of one control does not automatically expose sensitive
information. Which principle does this BEST demonstrate?
A. Defense in depth
B. Open design
C. Economy of mechanism
D. Separation of duties
Answer: A
4. A system rejects an access request whenever authorization
information is unavailable instead of granting access automatically.
Which principle is MOST directly demonstrated?
A. Least common mechanism
B. Fail securely
C. Open design
,3|Page
D. Psychological acceptability
Answer: B
5. A development team creates a data-flow diagram showing external
entities, processes, data stores, and communication paths before
implementing a new application. What security activity is this MOST
useful for?
A. Threat modeling
B. Performance benchmarking
C. User acceptance testing
D. Capacity planning
Answer: A
6. During threat modeling, a team identifies an attacker who could
impersonate a legitimate user and gain unauthorized access to an
account. Which STRIDE category BEST represents this threat?
A. Tampering
B. Repudiation
C. Spoofing
, 4|Page
D. Information disclosure
Answer: C
7. An attacker modifies transaction data while it is being processed,
causing an incorrect payment amount to be recorded. Which STRIDE
category BEST describes this threat?
A. Tampering
B. Spoofing
C. Repudiation
D. Denial of service
Answer: A
8. A user performs an unauthorized transaction and later claims that
the transaction never occurred. Which security concern is MOST
directly involved?
A. Spoofing
B. Repudiation
C. Elevation of privilege
D. Information disclosure