WGU D487 Oa 2026/2027 Test Bank With Questions And Correct Answers (100% Correct Verified
Answers) D487 Secure Software Design Objective Assessment 2026/2027 Test Bank V3
2026/2027 Official Exam
A+ 5 100%
QUESTIONS EXAM DOMAINS RATIONALES
VERIFIED COVERED INCLUDED
CATEGORIES
■ Section 1: SDLC Security Principles, Frameworks & Secure Design (Q1–14)
■ Section 2: Threat Modeling & Risk Assessment (Q15–28)
■ Section 3: Secure Coding, Vulnerabilities & Controls (Q29–42)
■ Section 4: Security Testing Methodologies & Test Planning (Q43–56)
■ Section 5: DevSecOps, Agile Integration & Post-Release (Q57–70)
STUVIAACTUALEXAM
Original practice content aligned to publicly described WGU D487 Secure Software Design competencies. Not an official WGU product.
, SECTION 1: SDLC SECURITY PRINCIPLES, FRAMEWORKS & SECURE DESIGN
Q1. A software organization wants to embed security activities into every phase of development rather than treating security as a
final gate. This approach is best described as:
A. Deferring all security work until after release to maximize feature velocity.
B. Relying solely on penetration testing of production systems.
C. Outsourcing security reviews only when a breach occurs.
D. Security by design (or building security in) across the software development life cycle.
Correct Answer: D
Rationale: Security by design integrates controls and reviews throughout the SDLC so defects are found and fixed earlier and more cheaply.
Q2. The Microsoft Security Development Lifecycle (SDL) is characterized primarily by:
A. A hardware-only certification program unrelated to software.
B. A set of mandatory security activities and gates mapped to development phases from requirements through release and response.
C. A single post-release audit with no upstream activities.
D. A purely optional checklist with no organizational accountability.
Correct Answer: B
Rationale: Microsoft SDL defines structured, phase-aligned security practices and release criteria.
Q3. BSIMM (Building Security In Maturity Model) differs from a prescriptive standard in that it:
A. Observes and measures real-world software security practices across organizations to enable benchmarking rather than prescribing
a single required process.
B. Mandates identical tools and headcount for every company regardless of size.
C. Replaces the need for any threat modeling or testing.
D. Applies only to open-source projects and ignores commercial software.
Correct Answer: A
Rationale: BSIMM is a descriptive maturity model based on observed activities, useful for comparison and improvement planning.
Q4. OWASP SAMM (Software Assurance Maturity Model) helps an organization by:
A. Providing a structured framework to assess and improve software security practices across governance, design, implementation,
verification, and operations.
B. Listing only the top ten web vulnerabilities without process guidance.
C. Requiring purchase of a specific commercial scanner.
D. Focusing exclusively on physical data-center security.
Correct Answer: A
Rationale: SAMM offers measurable security practice areas and a roadmap for maturity improvement.
Q5. The principle of least privilege in secure software design means that:
A. Every component, process, and user is granted only the minimum permissions needed to perform its function.
B. Permissions are never reviewed after initial deployment.
C. Services run as root or SYSTEM by default.
D. All users receive administrative rights for convenience.
Correct Answer: A
Rationale: Least privilege limits the damage from compromise or misuse of any single identity or component.
Q6. Economy of mechanism as a secure design principle emphasizes:
A. Hiding complexity behind undocumented interfaces.
B. Duplicating security controls without analysis.
C. Keeping designs as simple and small as practical so they are easier to understand, verify, and secure.
D. Adding as many features as possible to increase complexity.
Correct Answer: C
Rationale: Simple mechanisms reduce the chance of subtle flaws and ease assurance.
STUVIAACTUALEXAM | Page 2 of 14