• Wrong document? Swap it for free
  • Written by students who passed
  • Immediately available after payment
  • Read online or as PDF
Sell
Where do you study
Your language
Document preview thumbnail
Preview 3 out of 27 pages
Exam (elaborations)

WGU D487 Objective Assessment OA Exam Nursing 2026/2027 – Questions and Answers | 100% Verified | Detailed Rationales – Pass Guaranteed – A+ Graded

Document preview thumbnail
Preview 3 out of 27 pages

WGU D487 Objective Assessment OA Exam Nursing 2026/2027 – Questions with Answers | 100% Correct | Nursing Practice, Clinical Reasoning, Patient Safety, Assessment, Ethics, Safety | Graded A+ Verified | Evidence-Based Practice, Care Coordination, Leadership, Informatics, Policy, Quality | Detailed Rationales | Verified Correct Answers – Pass Guaranteed – Instant Download

Content preview

SECURE SOFTWARE DESIGN · OBJECTIVE ASSESSMENT
A+ VERIFIED

WGU D487 OA 2026/2027 Test Bank 3
— Complete
Official Exam Test Bank
150 Questions Full Rationales Verified Answers V3




A+ 6 100%
QUESTIONS SECTIONS RATIONALES
Complete coverage Core exam domains Every answer explained



WHAT THIS COVERS
01 Secure Design Principles & Architecture

02 Threat Modeling & Risk Assessment

03 Authentication, Authorization & Access Control

04 Cryptography & Data Protection

05 Secure Coding Practices & Input Validation

06 Security Testing, Code Review & Vulnerability Management




ABOUT THIS ASSESSMENT
Build mastery in secure software design — from secure design principles and
architecture to threat modeling, risk assessment, authentication, authorization,
access control, cryptography, data protection, secure coding practices, input
validation, security testing, code review, and vulnerability management. This
original study bank targets application and analysis skills for the WGU D487
Objective Assessment, with full rationales for every answer. For review use only;
not an institutional proctored assessment.




PASSING SCORE LEVEL FORMAT
80% Advanced (Secure Software Design) Application / Analysis

STUVIA ACTUAL EXAM Page 1

,SECTION 1: Secure Design Principles & Architecture

Q1. A development team is designing a new payment-processing microservice. The architect insists that the service should never trust data
received from the client and must validate every input at the boundary. This decision primarily implements which secure design
principle?
A. Defense in depth by adding multiple network layers only
B. Least privilege applied only to database accounts
C. Security through obscurity by hiding validation logic
D. Complete mediation and distrust of client input at trust boundaries
Correct Answer: D
Rationale: Validating every input at the service boundary enforces complete mediation and the principle of never trusting data that crosses a trust boundary.
Defense in depth is broader; obscurity and least privilege address different concerns.

Q2. During architecture review a senior engineer recommends that the authentication service run with only the permissions required to
issue tokens and nothing more. Which principle is being applied?
A. Least privilege limiting each component to minimum necessary rights
B. Fail-safe defaults that open access on error
C. Open design that publishes all algorithms
D. Separation of duties for human operators only
Correct Answer: A
Rationale: Least privilege requires that every component be granted only the permissions it needs to perform its function. Restricting the authentication service
to token issuance is a direct application of this principle.

Q3. A team is choosing between a monolithic architecture and a set of microservices for a high-sensitivity healthcare application. The
security architect argues for microservices because a compromise of one service need not expose all data. This argument rests
primarily on which principle?
A. Economy of mechanism favoring simplicity above all
B. Psychological acceptability for end users
C. Isolation and compartmentalization to limit blast radius
D. Complete mediation of every request
Correct Answer: C
Rationale: Isolation and compartmentalization reduce the impact of a single component compromise. Microservices, when properly segmented, embody this
principle by limiting lateral movement and data exposure.

Q4. An application design requires that every privileged operation be checked against the current authorization policy at the moment of use
rather than only at login. This requirement implements which foundational concept?
A. Security through obscurity
B. Fail-open behavior on policy-service failure
C. Complete mediation ensuring every access is checked
D. Client-side only authorization
Correct Answer: C
Rationale: Complete mediation demands that every access to every object be checked against the protection scheme. Checking policy at the moment of use,
not merely at session start, satisfies this requirement.

Q5. A design document states that the system should remain in a secure state when any component fails or is forced offline. The team
therefore implements circuit breakers that deny access rather than allow unrestricted traffic. Which principle is demonstrated?
A. Psychological acceptability
B. Least common mechanism
C. Open design
D. Fail-safe / fail-closed defaults
Correct Answer: D
Rationale: Fail-safe defaults (also called fail-closed) require that the system default to a secure state on failure. Circuit breakers that deny rather than allow
traffic implement this principle.

Q6. The architecture team decides that the same authentication library will be used by every internal service rather than each team writing
its own. In addition to consistency, this decision supports which secure-design goal?
A. Economy of mechanism and reduction of redundant trusted code
B. Increasing attack surface through code duplication
C. Maximizing diversity of authentication logic
D. Hiding the authentication approach from reviewers
Correct Answer: A
Rationale: Economy of mechanism favors simple, shared, well-reviewed components over many independent implementations. A single vetted authentication
library reduces the amount of trusted code that must be maintained and audited.




STUVIA ACTUAL EXAM · Page 2

, Q7. A new feature requires temporary elevation of privilege for a batch job. The design specifies that elevation is granted only for the
duration of the job and is automatically revoked afterward. This pattern primarily enforces:
A. Permanent high-privilege service accounts
B. Unrestricted lateral movement
C. Client-side privilege management
D. Just-in-time and just-enough privilege with automatic revocation
Correct Answer: D
Rationale: Granting elevated rights only for the needed window and then revoking them implements just-in-time / just-enough privilege, a refinement of least
privilege that reduces the window of exposure.

Q8. During a design review the security architect rejects a proposal that stores long-lived API keys in client-side JavaScript. The rejection is
grounded in which principle?
A. Assuming the client environment is fully trusted
B. Fail-open behavior for missing keys
C. Security through obscurity of the key value
D. Never placing secrets in an untrusted execution environment
Correct Answer: D
Rationale: Client-side code runs in an untrusted environment under the user's control. Placing long-lived secrets there violates the principle of keeping secrets
out of untrusted components.

Q9. An API gateway is configured to reject any request that does not contain a valid, non-expired token, even if the backend service is
reachable. This configuration primarily supports:
A. Complete reliance on backend authorization alone
B. Defense in depth by enforcing authentication at an outer layer
C. Open design of the token format
D. Psychological acceptability for attackers
Correct Answer: B
Rationale: Enforcing authentication at the gateway adds an outer control layer, contributing to defense in depth. Even if a backend is misconfigured, the
gateway still blocks unauthenticated traffic.

Q10. A team is designing a multi-tenant SaaS platform. They decide that each tenant's data and processing will run in a separate logical
container with strict network and identity isolation. The dominant secure-design principle at work is:
A. Shared everything architecture for cost savings
B. Single shared database with only application-level filters
C. Strong isolation and separation of tenant resources
D. Client-side tenant selection without server checks
Correct Answer: C
Rationale: Strong isolation prevents one tenant from accessing or affecting another's data and processes. Logical containers with network and identity controls
implement compartmentalization for multi-tenancy.

Q11. The security design requires that all administrative interfaces be reachable only from a dedicated management network and never from
the public internet. This decision primarily implements:
A. Exposure of management surfaces to the internet for convenience
B. Network segmentation and reduced attack surface for privileged functions
C. Open design of administrative protocols
D. Fail-open access when the management network is down
Correct Answer: B
Rationale: Restricting administrative interfaces to a dedicated network segments privileged functions away from the public attack surface, reducing the
likelihood of remote compromise of management capabilities.

Q12. A design principle adopted by the team states that the system should minimize the amount of code that runs with elevated privileges.
Consequently, only a small privileged helper process performs cryptographic operations while the main application runs as a
non-privileged user. This approach is best described as:
A. Running the entire application as root for simplicity
B. Privilege bracketing and separation of privileged code
C. Client-side privilege escalation
D. Security through obscurity of the helper process
Correct Answer: B
Rationale: Privilege bracketing confines elevated rights to the smallest possible code path. Separating cryptographic operations into a small privileged helper
while the bulk of the application runs unprivileged is a classic application of this principle.




STUVIA ACTUAL EXAM · Page 3

Document information

Uploaded on
September 24, 2026
Number of pages
27
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$16.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
STUVIAACTUALEXAMS
3.5
(179)
Sold
1349
Followers
210
Items
10317
Last sold
1 day ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions