WGU D487 Oa 2026/2027 Test Bank With Questions And Correct Answers (100%
Correct Verified Answers) A+
D487 Secure Software Design Objective Assessment 2026/2027 Test Bank V3
A+ Verified Questions & Rationales · Secure SDLC · Threat Modeling · Secure Coding
A+ 5 100%
QUESTIONS VERIFIED EXAM DOMAINS COVERED RATIONALES INCLUDED
CATEGORIES
■ 1. Secure SDLC, SDL & Security Gates
■ 2. Threat Modeling & Risk Assessment
■ 3. Secure Coding & Common Vulnerabilities
■ 4. Security Testing (SAST, DAST, Fuzzing, Reviews)
■ 5. Privacy, Standards, Deployment & Post-Release
STUVIAACTUALEXAM
Passing Score: 75% · 1 Mark per Question · Application/Analysis Level
, SECTION 1: Secure SDLC, SDL & Security Gates
Q1. A development team is adopting Microsoft’s Security Development Lifecycle (SDL). During the requirements phase they must produce a document that
identifies privacy and security objectives for the product. This activity is best described as:
A. A post-release incident response plan.
B. Only writing unit tests for existing code.
C. Deferring all security work until penetration testing.
D. Defining security and privacy requirements so that they can be designed, implemented, and tested.
Correct Answer: D
Rationale: SDL requires early capture of security and privacy requirements so they drive design, implementation, and verification rather than being bolted on later.
Q2. In an Agile project the team wants to integrate security without abandoning short sprints. The most effective approach is to:
A. Run a full formal security review only after final release.
B. Embed security stories, threat-model updates, and automated security tests into each sprint as part of the Definition of Done.
C. Ignore security until the product backlog is empty.
D. Outsource all security decisions to a separate team that never joins stand-ups.
Correct Answer: B
Rationale: DevSecOps and secure Agile practices fold security activities into the regular cadence so that defects are found and fixed early.
Q3. A company compares its software security program to the Building Security In Maturity Model (BSIMM). BSIMM is best characterized as:
A. An observational maturity model derived from real organizations’ practices, used for benchmarking rather than prescription.
B. A mandatory government certification checklist.
C. A coding standard that replaces OWASP.
D. A single tool that automatically remediates vulnerabilities.
Correct Answer: A
Rationale: BSIMM describes what high-performing organizations actually do; teams use it to compare and improve their own activities, not as a rigid standard.
Q4. During the design phase of the SDL, a team performs an attack-surface analysis. The primary goal of this analysis is to:
A. Identify and minimize the entry points and interfaces an attacker could use to interact with the system.
B. Count lines of code only.
C. Replace all third-party libraries.
D. Generate marketing material about security features.
Correct Answer: A
Rationale: Attack-surface reduction limits the number and complexity of interfaces that must be defended, lowering overall risk.
Q5. A security gate in the SDL requires that high-severity findings from static analysis be remediated or formally accepted before the build is promoted. This
gate is an example of:
A. A quality checkpoint that enforces security criteria at a defined lifecycle milestone.
B. Optional documentation that can be skipped under schedule pressure.
C. A substitute for all dynamic testing.
D. A process used only after customer release.
Correct Answer: A
Rationale: Security gates (or checkpoints) ensure that defined security criteria are met before moving to the next phase, preventing accumulation of known high-risk issues.
Q6. The main difference between software security and application security is that:
A. They are identical terms with no practical distinction.
B. Application security only applies to mobile apps.
C. Software security focuses on building security into the product during development; application security often emphasizes protecting deployed applications (e.g.,
WAF, runtime defenses).
D. Software security is only about encryption algorithms.
Correct Answer: C
Rationale: Software security is proactive and development-centric; application security frequently includes operational protections around running systems.
Q7. A product team must decide when to perform final security sign-off before release. In a mature SDL, final security review typically occurs:
A. After verification activities (testing, code review, residual risk acceptance) and before release to production or customers.
B. Only after the product has been in production for six months.
C. Before any requirements are written.
D. Solely by the marketing department.
Correct Answer: A
Rationale: Final security review confirms that planned security activities were completed and that remaining risk is acceptable prior to release.
Q8. In a Waterfall project the security team is invited only at the end of coding for a one-week penetration test. The most significant risk of this approach is:
A. Testers will have nothing to do.
B. The penetration test will always pass.
C. Critical design and requirements flaws are discovered late, when remediation is most expensive and schedule pressure is highest.
D. Developers will write too many unit tests.
Correct Answer: C
Rationale: Late-only testing misses the chance to fix architectural issues cheaply; secure SDLC pushes security activities left.
WGU D487 Secure Software Design · Page 2