A+ VERIFIED
WGU D487 OA 2026/2027 Test Bank 3
— Complete
Official Exam Test Bank
150 Questions Full Rationales Verified Answers V3
A+ 6 100%
QUESTIONS SECTIONS RATIONALES
Complete coverage Core exam domains Every answer explained
WHAT THIS COVERS
01 Secure Design Principles & Architecture
02 Threat Modeling & Risk Assessment
03 Authentication, Authorization & Access Control
04 Cryptography & Data Protection
05 Secure Coding Practices & Input Validation
06 Security Testing, Code Review & Vulnerability Management
ABOUT THIS ASSESSMENT
Build mastery in secure software design — from secure design principles and
architecture to threat modeling, risk assessment, authentication, authorization,
access control, cryptography, data protection, secure coding practices, input
validation, security testing, code review, and vulnerability management. This
original study bank targets application and analysis skills for the WGU D487
Objective Assessment, with full rationales for every answer. For review use only;
not an institutional proctored assessment.
PASSING SCORE LEVEL FORMAT
80% Advanced (Secure Software Design) Application / Analysis
STUVIA ACTUAL EXAM Page 1
,SECTION 1: Secure Design Principles & Architecture
Q1. A development team is designing a new payment-processing microservice. The architect insists that the service should never trust data
received from the client and must validate every input at the boundary. This decision primarily implements which secure design
principle?
A. Defense in depth by adding multiple network layers only
B. Least privilege applied only to database accounts
C. Security through obscurity by hiding validation logic
D. Complete mediation and distrust of client input at trust boundaries
Correct Answer: D
Rationale: Validating every input at the service boundary enforces complete mediation and the principle of never trusting data that crosses a trust boundary.
Defense in depth is broader; obscurity and least privilege address different concerns.
Q2. During architecture review a senior engineer recommends that the authentication service run with only the permissions required to
issue tokens and nothing more. Which principle is being applied?
A. Least privilege limiting each component to minimum necessary rights
B. Fail-safe defaults that open access on error
C. Open design that publishes all algorithms
D. Separation of duties for human operators only
Correct Answer: A
Rationale: Least privilege requires that every component be granted only the permissions it needs to perform its function. Restricting the authentication service
to token issuance is a direct application of this principle.
Q3. A team is choosing between a monolithic architecture and a set of microservices for a high-sensitivity healthcare application. The
security architect argues for microservices because a compromise of one service need not expose all data. This argument rests
primarily on which principle?
A. Economy of mechanism favoring simplicity above all
B. Psychological acceptability for end users
C. Isolation and compartmentalization to limit blast radius
D. Complete mediation of every request
Correct Answer: C
Rationale: Isolation and compartmentalization reduce the impact of a single component compromise. Microservices, when properly segmented, embody this
principle by limiting lateral movement and data exposure.
Q4. An application design requires that every privileged operation be checked against the current authorization policy at the moment of use
rather than only at login. This requirement implements which foundational concept?
A. Security through obscurity
B. Fail-open behavior on policy-service failure
C. Complete mediation ensuring every access is checked
D. Client-side only authorization
Correct Answer: C
Rationale: Complete mediation demands that every access to every object be checked against the protection scheme. Checking policy at the moment of use,
not merely at session start, satisfies this requirement.
Q5. A design document states that the system should remain in a secure state when any component fails or is forced offline. The team
therefore implements circuit breakers that deny access rather than allow unrestricted traffic. Which principle is demonstrated?
A. Psychological acceptability
B. Least common mechanism
C. Open design
D. Fail-safe / fail-closed defaults
Correct Answer: D
Rationale: Fail-safe defaults (also called fail-closed) require that the system default to a secure state on failure. Circuit breakers that deny rather than allow
traffic implement this principle.
Q6. The architecture team decides that the same authentication library will be used by every internal service rather than each team writing
its own. In addition to consistency, this decision supports which secure-design goal?
A. Economy of mechanism and reduction of redundant trusted code
B. Increasing attack surface through code duplication
C. Maximizing diversity of authentication logic
D. Hiding the authentication approach from reviewers
Correct Answer: A
Rationale: Economy of mechanism favors simple, shared, well-reviewed components over many independent implementations. A single vetted authentication
library reduces the amount of trusted code that must be maintained and audited.
STUVIA ACTUAL EXAM · Page 2
, Q7. A new feature requires temporary elevation of privilege for a batch job. The design specifies that elevation is granted only for the
duration of the job and is automatically revoked afterward. This pattern primarily enforces:
A. Permanent high-privilege service accounts
B. Unrestricted lateral movement
C. Client-side privilege management
D. Just-in-time and just-enough privilege with automatic revocation
Correct Answer: D
Rationale: Granting elevated rights only for the needed window and then revoking them implements just-in-time / just-enough privilege, a refinement of least
privilege that reduces the window of exposure.
Q8. During a design review the security architect rejects a proposal that stores long-lived API keys in client-side JavaScript. The rejection is
grounded in which principle?
A. Assuming the client environment is fully trusted
B. Fail-open behavior for missing keys
C. Security through obscurity of the key value
D. Never placing secrets in an untrusted execution environment
Correct Answer: D
Rationale: Client-side code runs in an untrusted environment under the user's control. Placing long-lived secrets there violates the principle of keeping secrets
out of untrusted components.
Q9. An API gateway is configured to reject any request that does not contain a valid, non-expired token, even if the backend service is
reachable. This configuration primarily supports:
A. Complete reliance on backend authorization alone
B. Defense in depth by enforcing authentication at an outer layer
C. Open design of the token format
D. Psychological acceptability for attackers
Correct Answer: B
Rationale: Enforcing authentication at the gateway adds an outer control layer, contributing to defense in depth. Even if a backend is misconfigured, the
gateway still blocks unauthenticated traffic.
Q10. A team is designing a multi-tenant SaaS platform. They decide that each tenant's data and processing will run in a separate logical
container with strict network and identity isolation. The dominant secure-design principle at work is:
A. Shared everything architecture for cost savings
B. Single shared database with only application-level filters
C. Strong isolation and separation of tenant resources
D. Client-side tenant selection without server checks
Correct Answer: C
Rationale: Strong isolation prevents one tenant from accessing or affecting another's data and processes. Logical containers with network and identity controls
implement compartmentalization for multi-tenancy.
Q11. The security design requires that all administrative interfaces be reachable only from a dedicated management network and never from
the public internet. This decision primarily implements:
A. Exposure of management surfaces to the internet for convenience
B. Network segmentation and reduced attack surface for privileged functions
C. Open design of administrative protocols
D. Fail-open access when the management network is down
Correct Answer: B
Rationale: Restricting administrative interfaces to a dedicated network segments privileged functions away from the public attack surface, reducing the
likelihood of remote compromise of management capabilities.
Q12. A design principle adopted by the team states that the system should minimize the amount of code that runs with elevated privileges.
Consequently, only a small privileged helper process performs cryptographic operations while the main application runs as a
non-privileged user. This approach is best described as:
A. Running the entire application as root for simplicity
B. Privilege bracketing and separation of privileged code
C. Client-side privilege escalation
D. Security through obscurity of the helper process
Correct Answer: B
Rationale: Privilege bracketing confines elevated rights to the smallest possible code path. Separating cryptographic operations into a small privileged helper
while the bulk of the application runs unprivileged is a classic application of this principle.
STUVIA ACTUAL EXAM · Page 3