• Wrong document? Swap it for free
  • Written by students who passed
  • Immediately available after payment
  • Read online or as PDF
Sell
Where do you study
Your language
Document preview thumbnail
Preview 3 out of 17 pages
Exam (elaborations)

WGU D385 Task 2 Complete Practice Guide | Vulnerability Identification & Remediation | API Security, Python Testing & Verification | 2026

Document preview thumbnail
Preview 3 out of 17 pages

This document provides a complete practice guide for WGU D385 Software Security & Testing Task 2, focusing on vulnerability identification and secure remediation. It covers API security, Python-based testing, vulnerability analysis, remediation techniques, and verification. The material is designed to help students prepare for Task 2 by practicing practical security testing and understanding how identified vulnerabilities can be securely addressed and verified.

Content preview

WGU D385 Software Security & Testing

Task 2 Complete Practice Guide
Vulnerability Identification & Remediation | API Security, Python Testing & Verification |
2026 | 2027




Institution Western Governors University (WGU)

Course D385 - Software Security & Testing

Assessment Task 2 - Vulnerability Identification & Remediation

Academic Year

Total Questions 40 (4 sections x 10)

Cognitive Mix 30% recall | 50% application | 20% analysis

Question Style 75% scenario-based | 25% direct

Aligned Standards OWASP Top 10 (2021), OWASP API Security Top 10 (2023), NIST SSDF

Tooling Python, Pytest, Pydantic, Bandit, OWASP ZAP, pip-audit, Sigstore

Document Type Complete Practice Guide + Exemplar + Grading Rubric

Total Points 100 (2.5 pts per question)



Scope. This guide provides a scenario-driven, hands-on practice set for the WGU D385 Task 2
performance assessment: identifying OWASP Top 10 vulnerabilities in Python code and API
responses, writing secure remediation, and constructing Pytest verification scripts. It integrates
the 2026/2027 updates including AI-assisted code remediation, software supply chain security
(Sigstore, hash-pinned dependencies), and zero-trust API architectures.

How to use. Attempt all 40 questions before consulting Part 2 (Exemplar) or Part 3 (Grading
Rubric). Each rationale explains the exact vulnerability mechanism, the secure Pythonic fix,
and why distractors represent insecure code, broken tests, or flawed security practices.




WGU D385 Task 2 | 2026 | 2027

, WGU D385 Task 2 | Vulnerability Identification & Remediation | 2026 Complete Practice Guide



Table of Contents
Part Content Page Reference

Cover Title page and guide metadata 1

Part 1 40-Question Practice Guide (Q1-Q40) 3

Section 1: Vulnerability Identification & OWASP Top 10 (Q1-Q10) 3

Section 2: API Security & Authentication Flaws (Q11-Q20) 6

Section 3: Python Remediation & Pytest Verification (Q21-Q30) 9

Section 4: DevSecOps & 2026 Updates (Q31-Q40) 12

Part 2 Complete Solution (Exemplar Answer Key) 15

Part 3 Grading Rubric & Solution Key 17




Page 2

, WGU D385 Task 2 | Vulnerability Identification & Remediation | 2026 Complete Practice Guide



Part 1: Complete Practice Guide (40 Questions)
Instructions: Select the single best answer (A-D) for each question. Each question is worth 2.5
points (100 points total). Mark answers on a separate sheet before verifying with Part 2 and
Part 3.


Section 1: Vulnerability Identification & OWASP Top 10 Analysis

Q1: A Python Flask route builds SQL as: `query = "SELECT * FROM users WHERE email='" +
email + "'"`. An attacker submits `' OR '1'='1`. Which OWASP Top 10 (2021) vulnerability is this,
and what is the secure fix?
A. Broken Access Control; fix with role checks
B. Injection (A03:2021); fix with parameterized queries / prepared statements
[CORRECT]
C. Security Misconfiguration (A05:2021); fix by patching the DB
D. Identification & Authentication Failures; fix with MFA
Correct Answer: B
Rationale: String-concatenated SQL is the canonical Injection (A03:2021) flaw; parameterized
queries separate code from data, neutralizing tautology payloads. Option A is object/function
access; Option C is config hardening, not query construction; Option D addresses login, not query
injection.

Q2: A route returns `render_template_string(user_input)` where user_input is
attacker-controlled. The attacker submits `{{ config.SECRET_KEY }}`. Which vulnerability and
remediation apply?
A. XSS; sanitize with bleach
B. Server-Side Template Injection (SSTI) under Injection (A03); use autoescaping
templates and never render untrusted input as a template [CORRECT]
C. CSRF; add a CSRF token
D. Insecure Deserialization; use JSON
Correct Answer: B
Rationale: render_template_string evaluates user input as a Jinja2 template, allowing SSTI that
can leak secrets or execute code; the fix is to pass user input as data to a pre-defined template
with autoescaping. Option A treats it as browser XSS; Option C is cross-site request forgery;
Option D is unrelated to template evaluation.

Q3: An application accepts pickle.loads(request.data) on a public endpoint. Which vulnerability
class and the secure replacement?
A. Injection; replace with regex
B. Insecure Deserialization (A08:2021); use a safe format like JSON with schema
validation [CORRECT]
C. Broken Authentication; replace pickle with hashlib
D. SSRF; block internal IPs
Correct Answer: B
Rationale: pickle.loads on untrusted data permits arbitrary code execution (A08:2021 Insecure
Deserialization); the fix is JSON (or protocol buffers) plus schema validation. Option A is the
wrong class; Option C is unrelated; Option D is outbound request forgery.


Page 3

Document information

Uploaded on
September 10, 2026
Number of pages
17
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$16.49

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
davidmiles
3.0
(3)
Sold
22
Followers
0
Items
637
Last sold
2 days ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions