A+ VERIFIED
WGU D487 OA 2026/2027 Test Bank 3
— Complete
Official Exam Test Bank
150 Questions Full Rationales Verified Answers V3
A+ 6 100%
QUESTIONS SECTIONS RATIONALES
Complete coverage Core exam domains Every answer explained
WHAT THIS COVERS
01 Secure Design Principles & Architecture
02 Threat Modeling & Risk Assessment
03 Authentication, Authorization & Access Control
04 Cryptography & Data Protection
05 Secure Coding Practices & Input Validation
06 Security Testing, Code Review & Vulnerability Management
ABOUT THIS ASSESSMENT
Build mastery in secure software design — from secure design principles and architecture to threat modeling, risk assessment,
authentication, authorization, access control, cryptography, data protection, secure coding practices, input validation, security testing, code
review, and vulnerability management. This original study bank targets application and analysis skills for the WGU D487 Objective
Assessment, with full rationales for every answer. For review use only; not an institutional proctored assessment.
PASSING SCORE LEVEL FORMAT
80% Advanced (Secure Software Design) Application / Analysis
STUVIA ACTUAL EXAM Page 1
, SECTION 1: Secure Design Principles & Architecture
Q1. A development team is designing a new payment-processing service. The lead architect insists that every component must fail in
a way that limits damage and that no single component should be able to compromise the entire system. This requirement most
directly reflects which secure design principle?
A. Fail-secure and least privilege combined with defense in depth
B. Complete mediation only
C. Security through obscurity
D. Open design without isolation
Correct Answer: A
Rationale:
Fail-secure behavior and compartmentalization (defense in depth / least privilege) ensure that a failure or breach in one component does not
cascade. Security through obscurity and open design alone do not provide isolation.
Q2. During an architecture review the security engineer notes that the proposed system trusts the client to send only valid session
tokens and never re-validates them on the server. Which secure design principle is being violated?
A. Psychological acceptability
B. Economy of mechanism
C. Complete mediation
D. Open design
Correct Answer: C
Rationale:
Complete mediation requires that every access to every object be checked. Relying on the client without server-side re-validation violates this
principle.
Q3. A team is choosing between a monolithic architecture and a microservices architecture for a high-security application. The security
architect argues that microservices allow finer-grained isolation of sensitive functions. This argument primarily supports which
principle?
A. Security through obscurity
B. Separation of duties and least privilege through isolation
C. Work-factor principle only
D. Least common mechanism without isolation
Correct Answer: B
Rationale:
Isolating sensitive functions into separate services reduces the blast radius of a compromise and supports least privilege and separation of critical
functions.
Q4. An application stores encryption keys in the same configuration file as the ciphertext they protect. A reviewer flags this as a
violation of which principle?
A. Psychological acceptability
B. Least astonishment
C. Open design
D. Separation of privileges / key separation
Correct Answer: D
Rationale:
Cryptographic keys must be separated from the data they protect so that compromise of the data store does not automatically yield the keys.
Q5. The security requirements state that the system must continue to enforce access controls even when an administrator account is
compromised. Which design approach best satisfies this requirement?
A. Single super-user account with full privileges
B. Disabling all logging during administrative sessions
C. Multi-person control and dual authorization for critical operations
D. Hard-coding administrative credentials in the binary
Correct Answer: C
Rationale:
Dual control and separation of duties prevent a single compromised account from performing high-impact actions alone.
STUVIA ACTUAL EXAM · Page 2
, SECTION 1: Secure Design Principles & Architecture
Q6. A legacy system uses a single shared library for both authentication and business-logic calculations. The security team
recommends splitting these responsibilities. This recommendation aligns with which principle?
A. Least common mechanism
B. Security through obscurity
C. Complete mediation only
D. Fail-open design
Correct Answer: A
Rationale:
Least common mechanism reduces the amount of shared code that multiple users or functions depend on, limiting the impact of a flaw in that
shared component.
Q7. When evaluating a third-party identity provider, the architect asks whether the provider’s design is published and subject to public
scrutiny. This question addresses which classic secure-design principle?
A. Least privilege
B. Fail-secure defaults
C. Psychological acceptability
D. Open design
Correct Answer: D
Rationale:
The open-design principle holds that security should not depend on the secrecy of the design; public scrutiny strengthens confidence.
Q8. A new feature allows users to upload executable scripts that the server will run. The security architect rejects the feature because
it violates which fundamental principle?
A. Economy of mechanism
B. Least privilege and isolation of untrusted code
C. Complete mediation of file reads only
D. Open design of the script engine
Correct Answer: B
Rationale:
Allowing untrusted executable content to run on the server grants excessive privilege and breaks isolation between trust boundaries.
Q9. The team is debating whether to implement a complex custom encryption protocol or to use a well-vetted standard library. The
security lead cites which principle in favor of the standard library?
A. Economy of mechanism and avoid unnecessary complexity
B. Security through obscurity of a custom protocol
C. Least common mechanism only
D. Fail-open cryptography
Correct Answer: A
Rationale:
Economy of mechanism favors simple, well-understood solutions; custom cryptography is rarely justified and frequently flawed.
Q10. An API gateway is configured to reject all requests that do not present a valid token, returning a generic error. This default
behavior exemplifies which principle?
A. Fail-open for usability
B. Complete mediation of responses only
C. Fail-secure (deny by default)
D. Psychological acceptability of error messages
Correct Answer: C
Rationale:
Deny-by-default is the fail-secure posture: when authentication cannot be established, access is refused.
STUVIA ACTUAL EXAM · Page 3
, SECTION 1: Secure Design Principles & Architecture
Q11. A microservice that handles PII is placed in a separate network segment with strict egress rules. This architectural decision
primarily supports.
A. Security through obscurity of network topology
B. Defense in depth and isolation of sensitive data
C. Least astonishment for developers
D. Economy of mechanism only
Correct Answer: B
Rationale:
Network segmentation adds a layer of defense and limits the ability of a compromised service to exfiltrate data.
Q12. The design requires that every administrative action be logged with the identity of the actor and that logs be protected from
modification by the same administrators. This requirement implements.
A. Psychological acceptability of logging
B. Open design of the logging format
C. Least common mechanism for logs
D. Accountability and separation of duties for audit integrity
Correct Answer: D
Rationale:
Non-repudiation and integrity of audit trails require that actors cannot alter the records of their own actions.
Q13. A system is designed so that a temporary elevation of privilege automatically expires after a short time window. This mechanism
supports.
A. Complete mediation of every packet
B. Fail-open session handling
C. Least privilege and time-bound authorization
D. Security through obscurity of the timer
Correct Answer: C
Rationale:
Time-limited privileges reduce the window of exposure if credentials are compromised.
Q14. During a design review the team decides that password reset tokens must be single-use and short-lived. This decision primarily
mitigates.
A. Replay and session-fixation style attacks on the reset flow
B. Only offline brute-force of the password hash
C. SQL injection in the reset form
D. Cross-site scripting on the login page
Correct Answer: A
Rationale:
Single-use, short-lived tokens prevent an intercepted token from being reused later.
Q15. The architecture places a Web Application Firewall (WAF) in front of the application servers and also implements input validation
inside the application. This combination is an example of.
A. Security through obscurity
B. Least common mechanism
C. Fail-open filtering
D. Defense in depth
Correct Answer: D
Rationale:
Multiple independent layers of protection illustrate defense in depth.
STUVIA ACTUAL EXAM · Page 4