• Wrong document? Swap it for free
  • Written by students who passed
  • Immediately available after payment
  • Read online or as PDF
Sell
Where do you study
Your language
Document preview thumbnail
Preview 3 out of 20 pages
Exam (elaborations)

WGU D487 Secure Software Design OA V3 and Practice 2026/2027 – Questions and Answers | 100% Verified | Complete Verified Answers – Pass Guaranteed – A+ Graded

Document preview thumbnail
Preview 3 out of 20 pages

WGU D487 OA V3 2026/2027 – Questions with Answers | 100% Correct | Secure Software Design, Security Architecture, Threat Modeling, Risk Management | Graded A+ Verified | Secure SDLC, Encryption, Access Control, Code Review, Auditing | Detailed Rationales | Verified Correct Answers – Pass Guaranteed – Instant Download

Content preview

WGU OBJECTIVE ASSESSMENT · SECURE SOFTWARE DESIGN


WGU D487 Oa 2026/2027 Test Bank With Questions And
A+
Correct Answers (100% Correct Verified Answers) D487
Secure Software Design Objective Assessment 2026/2027 Test
Bank V3
Original high-fidelity practice examination aligned to the public D487 Secure Software Design competencies and SDL
framework. Application- and analysis-level items with full rationales.



A+ QUESTIONS 5 SECTIONS 100% RATIONALES
VERIFIED FULL COVERAGE DETAILED



CATEGORIES
■ 1. Security Methods within the SDLC — Agile, DevSecOps, BSIMM, SAMM, Defense-in-Depth
■ 2. Assessing Software Requirements and Risks — Privacy, Risk Register, Compliance Drivers
■ 3. Architecture Security Analysis & Threat Modeling — STRIDE, PASTA, DREAD, Trust Boundaries
■ 4. Software Security Test Planning & Execution — SAST, DAST, IAST, Fuzzing, SCA
■ 5. Testing Effectiveness, Compliance & Post-Release — Metrics, Disclosure, Residual Risk


STUVIAACTUALEXAM
Passing Score: 75% · Marks: 1 per question · Bloom: Application / Analysis

,Section 1: Security Methods within the SDLC

Q1. A mid-size fintech company is transitioning from a traditional waterfall development model to an Agile framework
while attempting to retain the rigor of its existing Security Development Lifecycle (SDL). The security team is concerned
that security gates will be skipped under sprint pressure. The CISO asks the secure software design lead to
recommend the most effective way to embed security activities without slowing velocity.
A. Replace all formal security gates with informal peer discussions at the end of each sprint
B. Map SDL security activities to Agile ceremonies and automate gates inside the continuous integration pipeline
C. Keep the full waterfall SDL schedule and run it in parallel with every Agile sprint
D. Defer all security testing until the final release candidate to protect sprint capacity
Correct Answer: B
Rationale: Mapping SDL activities to Agile ceremonies and automating gates in CI/CD preserves security rigor while supporting
rapid iteration. Informal discussions alone lack accountability, parallel waterfall schedules create duplication, and deferring testing
until the end reintroduces late-discovery risk that the SDL was designed to eliminate.

Q2. During an internal maturity assessment, a security architect compares the organization's software security program
against both BSIMM and SAMM. Leadership wants a model that provides concrete activity benchmarks drawn from
real-world organizations of similar size rather than a prescriptive roadmap of what the organization 'should' do next.
A. Select BSIMM because it measures observed activities across peer organizations
B. Adopt SAMM because it is designed exclusively for Agile teams
C. Use only the OWASP Top 10 checklist as the maturity framework
D. Create a proprietary model that ignores external benchmarking data
Correct Answer: A
Rationale: BSIMM is an observational model that catalogs activities actually performed by real organizations, making it ideal for
benchmarking. SAMM is more prescriptive and goal-oriented. Relying solely on the OWASP Top 10 or inventing a proprietary
model forgoes the comparative insight leadership requested.

Q3. A product owner is preparing the initial project charter for a new customer-facing payment portal. The secure
design lead must ensure that security and privacy considerations are explicitly captured before any architecture work
begins. Which SDL phase deliverable is the primary vehicle for documenting these early security and privacy
requirements?
A. The final penetration test report produced after code freeze
B. The threat modeling artifacts generated during the Architecture phase
C. The security assessment and initial risk profile produced in the Security Assessment phase
D. The post-release incident response playbook
Correct Answer: C
Rationale: The Security Assessment (A1) phase is the first formal SDL phase and produces the initial security and privacy
requirements, risk profile, and planned security activities. Threat modeling occurs later in Architecture (A2), penetration testing
occurs near the end, and post-release materials are produced after ship.

Q4. An organization that has historically followed a pure waterfall SDL is adopting DevSecOps practices. The security
team needs to identify which traditional SDL activity can be most effectively automated as a continuous,
pipeline-integrated control rather than remaining a discrete, human-gated review.
A. Executive-level privacy impact assessment sign-off
B. Final legal review of the end-user license agreement
C. Static application security testing (SAST) of every code commit
D. Annual board-level risk acceptance meeting
Correct Answer: C
Rationale: SAST can be fully automated and run on every commit or pull request inside a CI/CD pipeline, providing continuous
feedback. Executive privacy sign-offs, legal reviews, and board meetings remain human-gated activities that cannot be fully
automated without losing accountability.




STUVIAACTUALEXAM | Page 2

, Q5. A software security group is updating its SDL policy to reflect modern practices. One stated goal of any mature
SDL is to reduce both the number of vulnerabilities that reach production and the severity of those that remain. Which
principle most directly supports this dual goal across every phase of development?
A. Deferring all security decisions until the testing phase to maximize developer freedom
B. Applying defense-in-depth so that multiple independent controls protect each asset
C. Relying exclusively on perimeter firewalls after deployment
D. Allowing each development team to invent its own security process from scratch
Correct Answer: B
Rationale: Defense-in-depth layers independent controls so that the failure of any single control does not result in total
compromise, simultaneously reducing the count of exploitable defects and limiting the impact of residual vulnerabilities. Late-only
security, perimeter-only thinking, and ad-hoc processes undermine both goals.

Q6. While reviewing the SDL project outline for a new mobile banking application, the project manager notices that
security activities are listed but have not been mapped to specific milestones on the master schedule. What is the
primary risk of leaving security activities unmapped to the development timeline?
A. The product may ship with higher-than-expected performance characteristics
B. Security tasks may be skipped or compressed when schedule pressure increases
C. Developers will automatically allocate extra time for security work
D. The marketing team will have more content for the launch campaign
Correct Answer: B
Rationale: When security activities are not explicitly scheduled, they are the first to be deferred or omitted under time pressure.
Mapping them to concrete milestones creates accountability and protects the integrity of the SDL.

Q7. A cross-functional team is debating whether to treat security requirements as functional or non-functional
requirements in the product backlog. The secure software design specialist explains the correct classification and its
practical consequence for prioritization.
A. Security requirements are non-functional quality attributes that must still be given explicit backlog priority and
acceptance criteria
B. Security requirements are purely functional and therefore always ranked above usability stories
C. Security requirements should never appear in the backlog because they belong only to the security team
D. Security requirements are optional and can be added after the product is released
Correct Answer: A
Rationale: Security requirements are classic non-functional requirements (quality attributes). They still require explicit prioritization,
sizing, and acceptance criteria; otherwise they are routinely deferred. Treating them as pure functional stories or excluding them
from the backlog both lead to incomplete security coverage.

Q8. An organization is implementing the Microsoft Security Development Lifecycle adapted for its own environment.
The security champion for a major product line must identify the earliest phase in which a formal threat model is
expected to be created and reviewed.
A. The Architecture phase once the high-level design is sufficiently defined
B. Post-release support after the first customer incident
C. The final ship review immediately before production deployment
D. Only during annual compliance audits
Correct Answer: A
Rationale: Threat modeling is a core activity of the Architecture (A2) phase. Performing it earlier lacks sufficient design detail;
performing it later (or only after incidents) defeats the purpose of identifying and mitigating threats before implementation.




STUVIAACTUALEXAM | Page 3

Document information

Uploaded on
September 13, 2026
Number of pages
20
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$16.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
STUVIAACTUALEXAMS
3.5
(179)
Sold
1349
Followers
210
Items
10317
Last sold
1 day ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions