Complete Study Guide + 60 Practice
Questions
Answers & Rationales |
Institution Western Governors University (WGU)
Course D385 - Software Security and Testing
Document Type Complete Study Guide + 60 Practice Questions
Academic Year
Total Questions 60 (4 sections x 15)
Cognitive Mix 30% recall | 50% application | 20% analysis
Question Style 75% scenario-based | 25% direct
Aligned Standards OWASP Top 10 (2021), OWASP API Top 10 (2023), NIST SSDF, CWE
Tooling Python, Pytest, Bandit, Flake8, SonarQube, OWASP ZAP, pip-audit, Sigstore
Total Points 100 (~1.67 pts per question)
Scope. This complete study guide provides comprehensive coverage of the entire WGU D385
course spectrum: from identifying an OWASP Top 10 vulnerability in a Python code snippet, to
writing the secure remediation, constructing the automated Pytest verification, and integrating it
into a DevSecOps pipeline. It integrates the latest 2026/2027 OWASP guidelines, modern
Python security libraries, contemporary API gateway configurations, and AI-driven security
updates.
How to use. Attempt all 60 questions before consulting Part 2 (Exemplar) or Part 3 (Grading
Rubric). Each rationale explains the exact vulnerability mechanism, the secure Pythonic fix, the
testing verification method, and why distractors represent insecure code, broken tests, or
flawed security practices.
WGU D385 | 2026 | 2027
, WGU D385 | Complete Study Guide + 60 Practice Questions | 2026/2027 Complete Study Guide
Table of Contents
Part Content Page Reference
Cover Title page and study guide metadata 1
Part 1 60-Question Study Guide (Q1-Q60) 3
Section 1: Security Fundamentals & OWASP Top 10 (Q1-Q15) 3
Section 2: SAST/DAST & Python Remediation (Q16-Q30) 8
Section 3: API Security & AuthN/AuthZ (Q31-Q45) 13
Section 4: Pytest, DevSecOps & 2026 Updates (Q46-Q60) 18
Part 2 Complete Solution (Exemplar Answer Key) 23
Part 3 Grading Rubric & Solution Key 25
Page 2
, WGU D385 | Complete Study Guide + 60 Practice Questions | 2026/2027 Complete Study Guide
Part 1: Complete Study Guide (60 Questions)
Instructions: Select the single best answer (A-D) for each question. Each question is worth
approximately 1.67 points (100 points total). Mark answers on a separate sheet before verifying
with Part 2 and Part 3.
Section 1: Software Security Fundamentals, OWASP Top 10, & Secure
Design
Q1: A Python Flask route builds SQL as query = "SELECT * FROM users WHERE
email='" + email + "'". An attacker submits ' OR '1'='1. Which OWASP Top 10
(2021) vulnerability is this, and what is the secure fix?
A. Broken Access Control; add role checks
B. Injection (A03:2021); use parameterized queries / prepared statements [CORRECT]
C. Security Misconfiguration (A05); patch the DB
D. Cryptographic Failures (A02); encrypt the query
Correct Answer: B
Rationale: String-concatenated SQL is the canonical Injection (A03:2021) flaw; parameterized
queries separate code from data, neutralizing tautology payloads. Option A is access control;
Option C is config hardening; Option D is crypto.
Q2: An endpoint GET /api/orders/{id} returns any order regardless of the requester, with
no ownership check. Which OWASP Top 10 (2021) category is this?
A. Broken Access Control (A01:2021) [CORRECT]
B. Cryptographic Failures (A02:2021)
C. Vulnerable & Outdated Components (A06)
D. Identification & Authentication Failures (A07)
Correct Answer: A
Rationale: Failing to verify ownership of an object is Broken Access Control (A01:2021) -
specifically IDOR/BOLA. Option B is crypto/transport; Option C is dependencies; Option D is
authentication.
Q3: An app stores passwords as hashlib.md5(pw.encode()).hexdigest(). Which
OWASP category and the secure fix?
A. Injection; parameterize
B. Cryptographic Failures (A02); use bcrypt/argon2 with a per-user salt [CORRECT]
C. Broken Access Control; add RBAC
D. Security Misconfiguration; disable debug
Correct Answer: B
Rationale: MD5 is fast and broken; password hashing requires slow, salted algorithms like
bcrypt/argon2. Options A, C, D are unrelated classes.
Page 3