Static Code Analysis & Flake8 Practice Lab
Python Security, Logging, Testing & Remediation | 2026 | 2027
Institution Western Governors University (WGU)
Course D385 - Software Security and Testing
Lab Title Static Code Analysis & Flake8 Practice Lab
Academic Year
Total Questions 40 (4 sections x 10)
Cognitive Mix 30% recall | 50% application | 20% analysis
Question Style 75% scenario-based | 25% direct
Aligned Standards PEP 8, OWASP Top 10 (2021), NIST SSDF, CWE
Tooling Python, Flake8, flake8-bandit, Bandit, Pytest, pre-commit, pip-audit
Document Type Practice Lab Workbook + Exemplar + Grading Rubric
Total Points 100 (2.5 pts per question)
Scope. This workbook provides a hands-on, scenario-driven practice lab for configuring
Flake8, interpreting static analysis reports, applying secure Python coding standards, and
verifying fixes with Pytest. It integrates 2026/2027 updates including AI-assisted code
formatting, flake8-bandit integration, RFC 7807 secure error handling, and automated
DevSecOps remediation workflows.
How to use. Attempt all 40 questions before consulting Part 2 (Exemplar) or Part 3 (Grading
Rubric). Each rationale explains the exact Flake8 rule or security vulnerability, the secure
Pythonic fix, and why distractors represent insecure code, broken configurations, or flawed
testing practices.
WGU D385 | 2026 | 2027
, WGU D385 | Static Code Analysis & Flake8 Practice Lab | 2026 Practice Lab Workbook
Table of Contents
Part Content Page Reference
Cover Title page and lab metadata 1
Part 1 40-Question Practice Lab Workbook (Q1-Q40) 3
Section 1: Flake8 Fundamentals & Configuration (Q1-Q10) 3
Section 2: Python Security & Linting Rules (Q11-Q20) 6
Section 3: Logging, Exception Handling & Audit (Q21-Q30) 9
Section 4: Testing, Remediation & 2026 Updates (Q31-Q40) 12
Part 2 Complete Solution (Exemplar Answer Key) 15
Part 3 Grading Rubric & Solution Key 17
Page 2
, WGU D385 | Static Code Analysis & Flake8 Practice Lab | 2026 Practice Lab Workbook
Part 1: Practice Lab Workbook (40 Questions)
Instructions: Select the single best answer (A-D) for each question. Each question is worth 2.5
points (100 points total). Mark answers on a separate sheet before verifying with Part 2 and
Part 3.
Section 1: Static Code Analysis Fundamentals & Flake8 Configuration
Q1: A developer runs Flake8 on a module and sees the report app.py:14:5: E225
missing whitespace around operator. Which Flake8 prefix category does this finding
belong to, and what does it indicate?
A. F-prefix (pyflakes) - logical error detected
B. E-prefix (pycodestyle error) - PEP 8 style violation [CORRECT]
C. W-prefix (pycodestyle warning) - deprecated usage
D. C-prefix (complexity) - cyclomatic complexity exceeded
Correct Answer: B
Rationale: The E-prefix denotes pycodestyle errors (PEP 8 violations) such as E225 (missing
whitespace around operator). F-prefix (A) is pyflakes (unused imports/undefined names); W-prefix
(C) is warnings; C-prefix (D) is mccabe complexity (requires the plugin).
Q2: Which .flake8 configuration correctly ignores E501 (line too long) and W503 (line break
before binary operator) project-wide?
A. [flake8] max-line-length = 999
B. [flake8] ignore = E501, W503 [CORRECT]
C. [flake8] exclude = E501 W503
D. [flake8] select = E501, W503
Correct Answer: B
Rationale: The `ignore` key lists rule codes to suppress project-wide. Option A raises the line limit
(not a clean suppression and can hide other issues); `exclude` (C) excludes paths, not rules;
`select` (D) enables rules rather than ignoring them.
Q3: A developer wants to enforce Flake8 before every commit. Which integration is most
appropriate?
A. Running flake8 manually once a month
B. A pre-commit hook configured in .pre-commit-config.yaml running flake8
[CORRECT]
C. A cron job on the production server
D. Disabling Flake8 in CI to speed up commits
Correct Answer: B
Rationale: pre-commit hooks run Flake8 on staged files before each commit, catching issues at
the developer's workstation. Option A is too infrequent; Option C runs in the wrong environment;
Option D removes the gate entirely.
Page 3