• Wrong document? Swap it for free
  • Written by students who passed
  • Immediately available after payment
  • Read online or as PDF
Sell
Where do you study
Your language
Document preview thumbnail
Preview 2 out of 14 pages
Exam (elaborations)

WGU D487 Secure Software Design OA V2 and Practice 2026/2027 – Questions and Answers | 100% Verified | Detailed Rationales – Pass Guaranteed – A+ Graded

Document preview thumbnail
Preview 2 out of 14 pages

WGU D487 OA V2 2026/2027 – Questions with Answers | 100% Correct | Secure Software Design, Security Architecture, Threat Modeling, Risk Management | Graded A+ Verified | Secure SDLC, Encryption, Access Control, Code Review, Auditing | Detailed Rationales | Verified Correct Answers – Pass Guaranteed – Instant Download

Content preview

WGU OA • SECURE SOFTWARE DESIGN


WGU D487 OA 2026/2027 TEST BANK WITH
QUESTIONS AND CORRECT ANSWERS (100%
CORRECT VERIFIED ANSWERS) D487 SECURE
SOFTWARE DESIGN OBJECTIVE ASSESSMENT
2026/2027 TEST BANK V2 — 2026/2027 Official Exam A+
Official-Style WGU Objective Assessment • Passing Score 75%



A+ QUESTIONS 5 SECTIONS 100%
VERIFIED BALANCED RATIONALES



CATEGORIES
Secure Design Principles & Security Requirements
Threat Modeling & Risk Analysis
Common Vulnerabilities & Secure Coding Practices
Authentication, Authorization & Session Management
Cryptography, Secure Architecture Patterns & Secure SDLC




EXAM FORMAT & SCORING
• Question Format: Multiple-choice (A–D) | 1 mark per question
• Total Marks: 70 | Passing Score: 75% (53/70)
• Difficulty: Advanced WGU OA — Application & Analysis level
• High-yield secure software design domains prioritized
• Answer Distribution: Balanced A/B/C/D | Full item-specific rationales
• Brand: STUVIAACTUALEXAM | Year: 2026/2027 | WGU D487 aligned




STUVIAACTUALEXAM

, SECTION: SECURE DESIGN PRINCIPLES & SECURITY REQUIREMENTS
Q1. A development team is designing a multi-tenant SaaS billing module. The architect insists that every database query must
include the tenant identifier as a mandatory filter and that the application layer must never rely solely on the presentation tier to
enforce isolation. This design decision primarily implements the principle of complete mediation and least privilege across trust
boundaries.
A. Complete mediation and least privilege ensuring every access is checked against the correct tenant context
B. Economy of mechanism that favors a single shared query for all tenants
C. Psychological acceptability that prioritizes developer convenience over isolation
D. Open design that publishes the query structure so tenants can audit it
Correct Answer: A
Rationale: Requiring the tenant filter on every query and never trusting the UI alone ensures that authorization is enforced at the point of access
(complete mediation) and that each tenant’s data is accessible only with the minimum necessary privileges.

Q2. During a requirements workshop the product owner states that the system must “be secure.” The security architect responds by
converting that vague statement into measurable requirements such as “all authentication events shall be logged with user identity,
timestamp, and outcome” and “passwords shall be stored using a memory-hard adaptive hash with a unique salt.” The architect is
applying the practice of deriving testable security requirements from high-level goals.
A. Leaving security as a non-functional afterthought that is addressed only in testing
B. Translating vague security goals into specific, verifiable requirements that can be designed and tested
C. Assuming that compliance checklists automatically produce secure software
D. Deferring all security decisions until the penetration-test phase
Correct Answer: B
Rationale: Effective secure design begins with clear, testable security requirements. Vague statements must be refined into concrete, measurable
criteria that guide architecture, implementation, and verification.

Q3. A payment-processing service is designed so that if the fraud-detection subsystem becomes unavailable, the system rejects
new high-value transactions rather than allowing them to proceed unchecked. This behavior illustrates the fail-secure (fail-closed)
principle.
A. Fail-open design that permits transactions when the security control is unavailable
B. Defense in depth that adds a second identical fraud-detection service
C. Fail-secure design that denies the risky operation when the protective control cannot operate
D. Least common mechanism that shares the fraud engine with unrelated services
Correct Answer: C
Rationale: Fail-secure design ensures that the system remains in a safe state when a security control fails. For a payment system, rejecting
high-value transactions when fraud detection is down is the safer default.

Q4. An API gateway is configured to validate every incoming JWT, enforce rate limits, and strip unexpected headers before
forwarding the request to internal microservices. Internal services therefore do not need to re-implement the same edge checks. The
architecture is applying the principle of defense in depth while still centralizing certain security functions at the trust boundary.
A. Single point of failure with no residual controls inside the services
B. Complete elimination of security checks inside microservices
C. Reliance on network location alone as the sole trust criterion
D. Layered controls at the perimeter combined with the expectation that internal components still practice least privilege
Correct Answer: D
Rationale: Defense in depth does not prohibit centralizing controls at the edge; it requires that residual risk still be addressed by additional layers.
Internal services should continue to enforce authorization appropriate to their own data.

Q5. A team is debating whether to allow developers to bypass input validation “just for the admin interface.” The security architect
rejects the exception, citing the principle that security mechanisms should not be circumventable by privileged users without strong
additional controls and audit. The principle being upheld is that of least privilege and non-circumvention of security controls.
A. Refusal to create unchecked bypasses that undermine the security control for any user role
B. Psychological acceptability that makes the admin interface as convenient as possible
C. Economy of mechanism that encourages a single code path for all users
D. Open design that documents the bypass for future maintainers
Correct Answer: A
Rationale: Creating privileged bypasses of core security controls frequently leads to abuse or accidental exposure. Secure design requires that
even administrative functions operate within a controlled, auditable security context.

Q6. A new healthcare application must satisfy HIPAA Security Rule requirements for access control and audit. The security
requirements document therefore includes “unique user identification,” “automatic log-off after defined inactivity,” and “audit controls
that record and examine activity in systems containing ePHI.” These statements are examples of regulatory-driven security
requirements that must be traced into design and test cases.
A. Optional guidelines that the team may ignore if the schedule is tight
B. Mandatory security requirements derived from regulation that must be implemented and verified
C. Performance requirements unrelated to security
D. Marketing claims that do not affect the technical design
Correct Answer: B
Rationale: Regulated industries translate legal obligations into concrete security requirements. Those requirements must be allocated to
components, implemented, and later verified through testing and audit.




Page 1 of 13 | STUVIAACTUALEXAM

Document information

Uploaded on
September 9, 2026
Number of pages
14
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$15.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
STUVIAACTUALEXAMS
3.5
(179)
Sold
1349
Followers
210
Items
10317
Last sold
1 day ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions