WGU D487 OA 2026/2027
Test Bank With Questions And Correct Answers
(100% Correct Verified Answers)
D487 Secure Software Design Objective Assessment
2026/2027 Test Bank V3
Western Governors University — Secure Software Design OA A+
A+ 5 100%
QUESTIONS VERIFIED EXAM DOMAINS COVERED RATIONALES INCLUDED
CATEGORIES
1. SDLC Security & Secure Development Practices
2. Threat Modeling & Risk Assessment
3. Secure Coding, Vulnerabilities & OWASP
4. Security Testing, Analysis & Code Review
5. Architecture, Maturity Models, Privacy & Compliance
EXAM FOCUS
Microsoft SDL · Agile/DevSecOps · SAMM/BSIMM · STRIDE · PASTA · DREAD · Attack surface
SQL injection · XSS · CSRF · Secure password storage · SAST/DAST · Fuzzing · SCA · Pen testing
Zero trust · API gateway · Privacy impact assessment · PCI-DSS · Secure defaults · SBOM · NIST SSDF
Aligned to WGU D487 Secure Software Design competencies and publicly described OA topics
STUVIAACTUALEXAM
, SECTION 1: SDLC Security & Secure Development Practices
Q1. A development team is adopting the Microsoft Security Development Lifecycle (SDL). The practice that best exemplifies
integrating security early rather than bolting it on at the end is:
A. Running a single penetration test only after production release.
B. Relying solely on end-user bug reports after launch.
C. Deferring all code review until the maintenance phase.
D. Performing threat modeling and security requirements analysis during design and requirements phases.
Correct Answer: D
Rationale: SDL emphasizes security activities from the earliest phases. Threat modeling and security requirements in design catch issues when
they are cheapest to fix.
Q2. An organization wants to shift security left in an Agile environment. The most effective approach is to:
A. Add a separate six-month security phase after each sprint.
B. Embed security stories, automated security checks, and threat-model updates into each sprint and definition of done.
C. Disable all automated testing to speed delivery.
D. Perform security activities only on the final release candidate.
Correct Answer: B
Rationale: DevSecOps and secure Agile practices integrate security into every iteration rather than treating it as a late-stage gate.
Q3. A project manager asks why security requirements should be written alongside functional requirements. The strongest
rationale is that:
A. Explicit security requirements drive design decisions, test cases, and acceptance criteria so that security is measurable and verifiable.
B. Security requirements are optional and can be invented during coding.
C. Functional requirements already imply all necessary security controls.
D. Security requirements only apply to government contracts.
Correct Answer: A
Rationale: Documented security requirements make expectations clear, enable traceability, and allow verification that controls were implemented
correctly.
Q4. During the design phase a team discovers that a planned feature will process highly sensitive personal data. The appropriate
next step is to:
A. Conduct or update a privacy impact assessment and ensure privacy requirements and controls are incorporated into the design.
B. Ignore privacy until after launch.
C. Store the data in cleartext for performance reasons.
D. Outsource the feature without further analysis.
Correct Answer: A
Rationale: Privacy impact assessments identify risks to personal data early so that technical and procedural controls can be designed in rather
than retrofitted.
Q5. A company compares Waterfall and Agile for a security-critical product. A key advantage of integrating security into Agile is:
A. Frequent iterations allow continuous security feedback, automated testing, and rapid remediation of newly discovered issues.
B. Security is performed only once at the very end.
C. Change is forbidden after the initial requirements freeze.
D. Threat modeling is never needed.
Correct Answer: A
Rationale: Agile’s short cycles support continuous integration of security testing and quick response to findings, provided security is built into the
process.
STUVIAACTUALEXAM · Page 2