• Wrong document? Swap it for free
  • Written by students who passed
  • Immediately available after payment
  • Read online or as PDF
Sell
Where do you study
Your language
Document preview thumbnail
Preview 2 out of 11 pages
Exam (elaborations)

WGU D487 Secure Software Design OA V3 and Practice 2026/2027 – Questions and Answers | 100% Verified | Detailed Rationales – Pass Guaranteed – A+ Graded

Document preview thumbnail
Preview 2 out of 11 pages

WGU D487 OA V3 2026/2027 – Questions with Answers | 100% Correct | Secure Software Design, Security Architecture, Threat Modeling, Risk Management | Graded A+ Verified | Secure SDLC, Encryption, Access Control, Code Review, Auditing | Detailed Rationales | Verified Correct Answers – Pass Guaranteed – Instant Download

Content preview

WGU · SECURE SOFTWARE DESIGN OBJECTIVE ASSESSMENT

WGU D487 Oa 2026/2027 Test Bank With Questions And Correct Answers (100%
Correct Verified Answers) A+
D487 Secure Software Design Objective Assessment 2026/2027 Test Bank V3
A+ Verified Questions & Rationales · Secure SDLC · Threat Modeling · Secure Coding


A+ 5 100%
QUESTIONS VERIFIED EXAM DOMAINS COVERED RATIONALES INCLUDED



CATEGORIES
■ 1. Secure SDLC, SDL & Security Gates
■ 2. Threat Modeling & Risk Assessment
■ 3. Secure Coding & Common Vulnerabilities
■ 4. Security Testing (SAST, DAST, Fuzzing, Reviews)
■ 5. Privacy, Standards, Deployment & Post-Release


STUVIAACTUALEXAM
Passing Score: 75% · 1 Mark per Question · Application/Analysis Level

, SECTION 1: Secure SDLC, SDL & Security Gates

Q1. A development team is adopting Microsoft’s Security Development Lifecycle (SDL). During the requirements phase they must produce a document that
identifies privacy and security objectives for the product. This activity is best described as:
A. A post-release incident response plan.
B. Only writing unit tests for existing code.
C. Deferring all security work until penetration testing.
D. Defining security and privacy requirements so that they can be designed, implemented, and tested.
Correct Answer: D
Rationale: SDL requires early capture of security and privacy requirements so they drive design, implementation, and verification rather than being bolted on later.

Q2. In an Agile project the team wants to integrate security without abandoning short sprints. The most effective approach is to:
A. Run a full formal security review only after final release.
B. Embed security stories, threat-model updates, and automated security tests into each sprint as part of the Definition of Done.
C. Ignore security until the product backlog is empty.
D. Outsource all security decisions to a separate team that never joins stand-ups.
Correct Answer: B
Rationale: DevSecOps and secure Agile practices fold security activities into the regular cadence so that defects are found and fixed early.

Q3. A company compares its software security program to the Building Security In Maturity Model (BSIMM). BSIMM is best characterized as:
A. An observational maturity model derived from real organizations’ practices, used for benchmarking rather than prescription.
B. A mandatory government certification checklist.
C. A coding standard that replaces OWASP.
D. A single tool that automatically remediates vulnerabilities.
Correct Answer: A
Rationale: BSIMM describes what high-performing organizations actually do; teams use it to compare and improve their own activities, not as a rigid standard.

Q4. During the design phase of the SDL, a team performs an attack-surface analysis. The primary goal of this analysis is to:
A. Identify and minimize the entry points and interfaces an attacker could use to interact with the system.
B. Count lines of code only.
C. Replace all third-party libraries.
D. Generate marketing material about security features.
Correct Answer: A
Rationale: Attack-surface reduction limits the number and complexity of interfaces that must be defended, lowering overall risk.

Q5. A security gate in the SDL requires that high-severity findings from static analysis be remediated or formally accepted before the build is promoted. This
gate is an example of:
A. A quality checkpoint that enforces security criteria at a defined lifecycle milestone.
B. Optional documentation that can be skipped under schedule pressure.
C. A substitute for all dynamic testing.
D. A process used only after customer release.
Correct Answer: A
Rationale: Security gates (or checkpoints) ensure that defined security criteria are met before moving to the next phase, preventing accumulation of known high-risk issues.

Q6. The main difference between software security and application security is that:
A. They are identical terms with no practical distinction.
B. Application security only applies to mobile apps.
C. Software security focuses on building security into the product during development; application security often emphasizes protecting deployed applications (e.g.,
WAF, runtime defenses).
D. Software security is only about encryption algorithms.
Correct Answer: C
Rationale: Software security is proactive and development-centric; application security frequently includes operational protections around running systems.

Q7. A product team must decide when to perform final security sign-off before release. In a mature SDL, final security review typically occurs:
A. After verification activities (testing, code review, residual risk acceptance) and before release to production or customers.
B. Only after the product has been in production for six months.
C. Before any requirements are written.
D. Solely by the marketing department.
Correct Answer: A
Rationale: Final security review confirms that planned security activities were completed and that remaining risk is acceptable prior to release.

Q8. In a Waterfall project the security team is invited only at the end of coding for a one-week penetration test. The most significant risk of this approach is:
A. Testers will have nothing to do.
B. The penetration test will always pass.
C. Critical design and requirements flaws are discovered late, when remediation is most expensive and schedule pressure is highest.
D. Developers will write too many unit tests.
Correct Answer: C
Rationale: Late-only testing misses the chance to fix architectural issues cheaply; secure SDLC pushes security activities left.




WGU D487 Secure Software Design · Page 2

Document information

Uploaded on
September 12, 2026
Number of pages
11
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$17.49

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
STUVIAACTUALEXAMS
3.5
(179)
Sold
1349
Followers
210
Items
10317
Last sold
1 day ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions