• Wrong document? Swap it for free
  • Written by students who passed
  • Immediately available after payment
  • Read online or as PDF
Sell
Where do you study
Your language
Document preview thumbnail
Preview 4 out of 74 pages
Exam (elaborations)

WGU D487 Objective Assessment OA Exam Nursing Competency 2026/2027 – Questions and Answers | 100% Verified | Detailed Rationales – Pass Guaranteed – A+ Graded

Document preview thumbnail
Preview 4 out of 74 pages

WGU D487 Objective Assessment OA 2026/2027 – Questions with Answers | 100% Correct | Nursing Practice, Clinical Reasoning, Patient Safety, Assessment, Ethics | Graded A+ Verified | Evidence-Based Practice, Care Coordination, Leadership, Informatics, Policy | Detailed Rationales | Verified Correct Answers – Pass Guaranteed – Instant Download

Content preview

S E C U R E S O F T WA R E D E S I G N · O B J E C T I V E A S S E S S M E N T A+ VERIFIED

WGU D487 OA 2026/2027
Test Bank 3 — Complete
Official Exam Test Bank
150 Questions Full Rationales Verified Answers V3




A+ 6 100%
Q UES T I O N S S ECT I O N S R AT I O N AL E S
Complete coverage Core exam domains Every answer explained



WHAT THIS COVERS


01 Secure Design Principles & Architecture

02 Threat Modeling & Risk Assessment

03 Authentication, Authorization & Access Control

04 Cryptography & Data Protection

05 Secure Coding Practices & Input Validation

06 Security Testing, Code Review & Vulnerability Management



ABOUT THIS ASSESSMENT
Build mastery in secure software design — from secure design principles and architecture to threat modeling, risk assessment,
authentication, authorization, access control, cryptography, data protection, secure coding practices, input validation, security
testing, code review, and vulnerability management. This original study bank targets application and analysis skills for the WGU
D487 Objective Assessment, with full rationales for every answer. For review use only; not an institutional proctored assessment.



L E VE L
PAS S I N G S C O R E F O R M AT
80% Advanced (Secure Software Application / Analysis
Design)


S T UVI A ACT UAL EXAM Pa ge 1

, SECTION 1: SECURE DESIGN PRINCIPLES & ARCHITECTURE


Q1. A payments startup suffered a breach after a single WAF rule failure exposed an unpatched
admin console directly to the internet. The post-incident review found that every control protecting
the console depended on that one appliance. Which architectural change best demonstrates defense
in depth for this environment?
A. Replace the current WAF vendor with a competing cloud WAF and keep the remaining
architecture unchanged
B. Move the admin console to a static IP address and require the operations team to connect
only through that address
C. Layer the edge WAF with application-level input validation, a least-privilege service account
for the console, and independent monitoring alerts on admin access
D. Increase the WAF rule refresh frequency from weekly to daily and record the change in the
risk register
Correct Answer: C
Rationale: Defense in depth requires independent, overlapping controls so that one failure never exposes the
asset by itself. The layered option adds protection at the network, application, identity, and monitoring levels.
Swapping vendors or tuning a single appliance still leaves the console behind one point of failure.


Q2. During a code review, an engineer discovers that the customer-facing web application uses a
database account with full sysadmin rights because it made early development easier. The
application only ever reads and writes its own schema. What is the most appropriate secure design
correction?
A. Rotate the sysadmin credentials weekly and store the new values in an encrypted secrets
vault
B. Move the credentials into environment variables so the application no longer embeds them
in source code
C. Create a stored procedure that wraps the privileged operations and call it from the
application
D. Provision a dedicated application account scoped to the application schema with only the
required read and write grants
Correct Answer: D
Rationale: Least privilege means granting only the permissions a service actually needs, so the account must be
scoped to its own schema with minimal grants. This limits the blast radius if the web tier is compromised.
Rotating or relocating over-privileged credentials reduces some risk but leaves the excessive grants fully intact.




STUVIA ACTUAL EXAM · Page 2

,Q3. A single release engineer can approve pipeline changes, merge code to the main branch, and
deploy to production with no other checkpoints. An audit flags this as a systemic risk after a
near-miss unauthorized deployment. Which control design best addresses the finding?
A. Require a second authorized reviewer to approve production deployments separately from
code merge approval, enforced by pipeline policy
B. Ask the release engineer to document every deployment decision in a shared log for later
review
C. Give the release engineer read-only access to production to reduce the chance of accidental
changes
D. Deploy an automated scanner that reviews commits before the release engineer merges
them
Correct Answer: A
Rationale: Separation of duties splits critical actions across different people or enforced stages so one person
cannot both make and authorize a change. An independent production approval gate, enforced mechanically by
the pipeline, provides that split. Logging and read-only access add visibility, but neither prevents unilateral
deployment.


Q4. A building-access vendor installs a new electronic controller for a data center equipment room.
During a power failure the controller must decide whether the door stays locked. From a
data-protection standpoint, which fail behavior is correct for this door and why?
A. Fail-secure: the door remains locked on power loss because protecting the assets behind it is
the primary goal
B. Fail-safe: the door unlocks on power loss so an occupant is never trapped during an
emergency
C. Fail-open with an audible alarm so that the open state is at least visible to patrolling guards
D. Hold the last known state and restore it automatically when power returns to the controller
Correct Answer: A
Rationale: Fail-secure behavior is appropriate where confidentiality of the protected assets matters more than
immediate egress, with a mechanical override available for life safety. A data center equipment room prioritizes
keeping unauthorized people out during outages. Fail-safe egress belongs on occupied emergency exits, not on
containment doors.




STUVIA ACTUAL EXAM · Page 3

, Q5. A SaaS provider launches a new tenant environment in which every new account starts with a
public object-storage bucket, default administrator credentials, and verbose API error messages
enabled. Attackers enumerated dozens of tenants within the first week. Which secure design flaw
best describes the root cause?
A. Misconfigured logging: telemetry was not centralized, so the enumeration was hard to detect
B. Insecure defaults: the out-of-the-box configuration grants more access and disclosure than
users need
C. Missing patch management: the tenant instances were not patched during provisioning
D. Weak physical security: the underlying hardware lacked tamper-evident protection
Correct Answer: B
Rationale: When shipped settings start permissive and chatty, every tenant begins life overexposed, which is
the classic insecure-defaults flaw. Secure design requires deny-by-default baselines with exposure enabled only
on explicit request. Logging or patching gaps may exist, but they are not what enabled instant enumeration of
fresh tenants.


Q6. An enterprise wants to stop treating its corporate VPN as a trusted zone after attackers pivoted
freely from one compromised laptop to file servers. The CISO asks how the replacement architecture
should make access decisions. Which principle set defines that approach?
A. Microsegmentation alone: divide the network into small segments and trust traffic that stays
inside one segment
B. Network access control: quarantine noncompliant devices until their antivirus signatures
update
C. Zero trust: authenticate and authorize every request using identity, device posture, and
context, with no implicit trust from network location
D. Perimeter hardening: place a next-generation firewall between the VPN and the servers and
trust authenticated sessions
Correct Answer: C
Rationale: Zero trust removes implicit trust based on network location and evaluates each request on identity,
device health, and context. Microsegmentation and NAC are useful components but still anchor trust to a zone.
A hardened perimeter recreates the very model that just failed.




STUVIA ACTUAL EXAM · Page 4

Document information

Uploaded on
September 22, 2026
Number of pages
74
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$18.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
STUVIAACTUALEXAMS
3.5
(179)
Sold
1349
Followers
210
Items
10317
Last sold
1 day ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions