WGU D487 OA 2026/2027 Test Bank 3 — Complete
Official Exam Test Bank
150 Questions Full Rationales Verified Answers V3
A+ 6 100%
QUESTIONS SECTIONS RATIONALES
Complete coverage Core exam domains Every answer explained
WHAT THIS COVERS
01 Secure Design Principles & Architecture
02 Threat Modeling & Risk Assessment
03 Authentication, Authorization & Access Control
04 Cryptography & Data Protection
05 Secure Coding Practices & Input Validation
06 Security Testing, Code Review & Vulnerability Management
ABOUT THIS ASSESSMENT
Build mastery in secure software design — from secure design principles and architecture to threat modeling, risk assessment, authentication,
authorization, access control, cryptography, data protection, secure coding practices, input validation, security testing, code review, and
vulnerability management. This original study bank targets application and analysis skills for the WGU D487 Objective Assessment, with full
rationales for every answer. For review use only; not an institutional proctored assessment.
PASSING SCORE LEVEL FORMAT
80% Advanced (Secure Software Design) Application / Analysis
STUVIA ACTUAL EXAM Page 1
, SECTION 1: SECURE DESIGN PRINCIPLES & ARCHITECTURE
Q1. A development team is designing a new customer-facing payment portal. The architect insists that every component default to denying
access unless an explicit allow rule is present. A junior developer questions whether this adds unnecessary complexity. Which secure design
principle is the architect enforcing, and why does it matter for the payment portal?
A. Psychological acceptability; it prioritizes user convenience over any access restrictions.
B. Economy of mechanism; it forces the team to remove all authentication checks to simplify the code.
C. Fail-safe defaults; it ensures that a configuration error or incomplete rule set still leaves the system in a secure state rather than an open one.
D. Complete mediation; it requires every request to be checked against a central policy server on every call.
Correct Answer: C
Rationale: Fail-safe defaults (also called fail-closed) require that the system remain secure when configuration is incomplete or fails. For a payment portal this
prevents accidental exposure of sensitive financial functions. Complete mediation is related but focuses on continuous checking; the other options misstate the
principles.
Q2. During an architecture review for a multi-tenant SaaS platform, the security architect requires that each tenant’s data and processes
remain isolated so that a compromise in one tenant cannot affect others. The team is evaluating containerization, separate databases, and
network segmentation. Which design principle most directly drives this requirement?
A. Security through obscurity; tenant data should be hidden by proprietary encoding.
B. Least privilege applied at the tenant boundary; isolation limits the blast radius of any single compromise.
C. Open design; the architecture must be published so tenants can audit isolation mechanisms.
D. Defense in depth solely through perimeter firewalls; internal isolation is unnecessary.
Correct Answer: B
Rationale: Isolation between tenants is an application of least privilege and compartmentalization. A breach in one tenant must not grant access to others. Open
design is about not relying on secrecy of the design; the other options either weaken or misapply security principles.
Q3. A legacy monolithic application is being refactored into microservices. The security lead argues that each service should expose only the
minimum set of operations required by its consumers and should validate every incoming request independently. Which pair of secure design
principles is being applied?
A. Economy of mechanism and psychological acceptability.
B. Open design and security through obscurity.
C. Least privilege and complete mediation.
D. Fail-open defaults and single point of failure acceptance.
Correct Answer: C
Rationale: Least privilege limits the operations each service exposes; complete mediation ensures every request is checked. The other pairs either mix
unrelated principles or describe insecure practices.
Q4. An architect is evaluating whether to embed detailed security logic inside every business method or to centralize authorization decisions
in a dedicated policy enforcement point. The team wants to minimize the chance that a developer forgets a check. Which principle most
strongly favors the centralized approach?
A. Economy of mechanism combined with complete mediation; a single, well-tested enforcement point reduces the surface for errors.
B. Psychological acceptability; developers prefer writing their own checks for flexibility.
C. Fail-safe defaults; centralization is irrelevant to default behavior.
D. Open design; every method must publish its own authorization rules publicly.
Correct Answer: A
Rationale: Centralizing authorization reduces duplicated and potentially inconsistent checks, supporting both simplicity (economy of mechanism) and consistent
mediation. The other options do not correctly justify centralization.
Q5. A product owner wants the authentication service to remain available even if the secondary identity store is unreachable. The security
architect counters that availability must not override integrity of access decisions. Which CIA triad element is the architect prioritizing in this
discussion, and what is the correct trade-off stance?
A. None of the CIA elements apply to authentication decisions.
B. Integrity; the system should fail closed on authentication rather than grant access based on incomplete data.
C. Availability; the system must always grant access if any store is reachable.
D. Confidentiality; the discussion is solely about encrypting the identity store.
Correct Answer: B
Rationale: When identity data cannot be verified, granting access would violate integrity of the access-control decision. Fail-closed protects integrity; availability
is important but secondary in this scenario.
STUVIA ACTUAL EXAM · Page 2
, SECTION 1: SECURE DESIGN PRINCIPLES & ARCHITECTURE
Q6. During a design workshop the team discusses the principle that security mechanisms should not make the system so difficult to use that
users circumvent them. A proposed multi-factor scheme requires six sequential prompts for every login. Which principle is most at risk, and
what is a better design direction?
A. Complete mediation; remove all authentication to avoid friction.
B. Open design; publish the six-prompt sequence so users can memorize it.
C. Least privilege; reduce the number of factors so users have fewer privileges.
D. Psychological acceptability; streamline the user experience while retaining strong authentication (e.g., adaptive MFA or hardware keys).
Correct Answer: D
Rationale: Psychological acceptability requires that security controls be usable. Overly burdensome MFA often leads to work-arounds. The other principles are
not the primary concern here.
Q7. A new API gateway is being designed to sit in front of several internal microservices. The architect requires that the gateway validate
every request’s authentication token and authorization claims before forwarding traffic, and that internal services still perform their own
authorization checks. Which defense-in-depth concept is illustrated?
A. Security through obscurity by hiding the internal service endpoints.
B. Reliance on network segmentation only, with no application-layer checks.
C. Single point of enforcement that eliminates the need for any backend checks.
D. Layered controls so that compromise of the gateway alone does not grant unrestricted access to backend services.
Correct Answer: D
Rationale: Defense in depth places complementary controls at multiple layers. Gateway checks plus service-level checks ensure that a single failure does not
open the entire system.
Q8. An organization is adopting a zero-trust architecture for its internal applications. Every request, even from within the corporate network,
must be authenticated and authorized. Which traditional perimeter assumption is being deliberately abandoned?
A. The assumption that passwords are the only acceptable authenticator.
B. The assumption that encryption is never required on internal links.
C. The assumption that all users are external attackers.
D. The assumption that systems inside the network boundary can be implicitly trusted.
Correct Answer: D
Rationale: Zero trust rejects the idea of a trusted internal network. Every request is verified regardless of origin. The other statements mischaracterize zero-trust
principles.
Q9. A design document states that the system will use the simplest possible cryptographic primitives and protocols that still meet the security
requirements, avoiding custom or overly complex constructions. Which secure design principle is being followed?
A. Economy of mechanism; simpler designs are easier to analyze, implement correctly, and maintain.
B. Open design; the principle requires that all algorithms be secret.
C. Psychological acceptability; users must understand every cryptographic detail.
D. Complete mediation; every cryptographic operation must be checked by a central server.
Correct Answer: A
Rationale: Economy of mechanism favors simplicity because complex systems hide more bugs. Open design actually requires that the design be public; the
other options are incorrect applications.
Q10. A security architect is reviewing a proposed design in which administrative functions share the same authentication and session
management code paths as ordinary user functions. The architect recommends separating the administrative control plane. What is the
primary security benefit of this separation?
A. It guarantees that ordinary users can never be elevated to administrators.
B. It is required only for systems that process payment data.
C. It eliminates the need for any authentication on administrative functions.
D. It reduces the attack surface for privileged operations and allows stronger controls (e.g., step-up authentication, stricter logging) to be applied
only where needed.
Correct Answer: D
Rationale: Separating the control plane allows privileged operations to be protected by additional controls without burdening the main user path, and limits the
impact of a compromise of the user-facing authentication code.
STUVIA ACTUAL EXAM · Page 3
, SECTION 1: SECURE DESIGN PRINCIPLES & ARCHITECTURE
Q11. During an architecture assessment the team is asked to identify the single most important reason that security requirements must be
captured early in the SDLC rather than added after coding is complete.
A. Security is purely an operations concern and does not belong in design documents.
B. The cost and difficulty of remediation increase dramatically the later a security defect is discovered; early requirements enable design-level
mitigations.
C. Early requirements are useful only for compliance paperwork and have no technical impact.
D. Security requirements can only be written after the code is finished and tested.
Correct Answer: B
Rationale: Industry data consistently shows that fixing security issues in design is far cheaper than fixing them in production. Early requirements drive
architecture and coding decisions that prevent entire classes of vulnerabilities.
Q12. A microservice is designed so that it never trusts the caller’s assertion of the user’s identity; instead it always validates a signed token
issued by a trusted identity provider. Which secure design principle is most clearly demonstrated?
A. Psychological acceptability by letting the client decide identity.
B. Complete mediation and distrust of client-supplied identity claims.
C. Economy of mechanism by removing all authentication.
D. Open design by publishing the private signing key.
Correct Answer: B
Rationale: Never trusting client-supplied identity and always validating a cryptographically protected token is a direct application of complete mediation and the
principle of not trusting the client.
Q13. An architect is evaluating whether to implement a custom encryption library or to use a well-vetted open-source library that has
undergone public scrutiny. Which principle most strongly supports using the public library?
A. Security through obscurity; custom code is harder for attackers to understand.
B. Fail-safe defaults; open-source libraries always fail closed.
C. Open design; security should not depend on the secrecy of the algorithm or implementation, and public review improves confidence.
D. Least privilege; custom libraries automatically have fewer privileges.
Correct Answer: C
Rationale: Open design (Kerckhoffs’s principle) states that a system should remain secure even if everything except the key is known. Public libraries benefit
from broad review; custom crypto is rarely a good idea.
Q14. A design review identifies that a critical configuration file containing database credentials is readable by every process on the host. The
architect demands that the file be readable only by the specific service account that needs it. Which principle is being enforced?
A. Complete mediation of every database query.
B. Psychological acceptability of configuration management.
C. Economy of mechanism by sharing one credential file.
D. Least privilege applied to file-system permissions.
Correct Answer: D
Rationale: Restricting file permissions to the minimum necessary process is a classic application of least privilege. The other principles are not the primary
concern in this scenario.
Q15. A team is designing an online banking application. The security architect requires that the system remain secure even if an individual
component (for example, the session store) fails. Which design approach best satisfies this requirement?
A. Single point of failure acceptance for the session store.
B. Fail-safe (fail-closed) behavior for security-critical decisions combined with graceful degradation for non-security functions.
C. Removal of all session management to eliminate the failure mode.
D. Fail-open behavior so that users can always access their accounts.
Correct Answer: B
Rationale: Security-critical decisions should fail closed; availability of non-critical features can degrade gracefully. Fail-open for authentication would be
dangerous.
STUVIA ACTUAL EXAM · Page 4