• Wrong document? Swap it for free
  • Written by students who passed
  • Immediately available after payment
  • Read online or as PDF
Sell
Where do you study
Your language
Document preview thumbnail
Preview 4 out of 38 pages
Exam (elaborations)

WGU D487 OA Exam Nursing Competency Test Bank 2026/2027 – Questions and Answers | 100% Verified | Detailed Rationales – Pass Guaranteed – A+ Graded

Document preview thumbnail
Preview 4 out of 38 pages

WGU D487 OA Exam Nursing 2026/2027 – Questions with Answers | 100% Correct | Nursing Practice, Clinical Reasoning, Patient Safety, Assessment, Ethics, Safety | Graded A+ Verified | Evidence-Based Practice, Care Coordination, Leadership, Informatics, Policy | Detailed Rationales | Verified Correct Answers – Pass Guaranteed – Instant Download

Content preview

A+ VERIFIED
SECURE SOFTWARE DESIGN · OBJECTIVE ASSESSMENT


2026/2027 WGU D487 OA TEST BANK 2 — Complete
Official Exam Test Bank

150 Questions Full Rationales Verified Answers Test Bank 2




A+ 6 100%
QUESTIONS SECTIONS RATIONALES
Complete coverage Core exam domains Every answer explained




WHAT THIS COVERS

01 Secure Design Principles & Architecture

02 Threat Modeling & Risk Assessment

03 Authentication, Authorization & Access Control

04 Cryptography & Data Protection

05 Secure Coding Practices & Input Validation

06 Security Testing, Code Review & Vulnerability Management



ABOUT THIS ASSESSMENT
Build mastery in secure software design — from secure design principles and architecture to threat modeling, risk assessment,
authentication, authorization, access control, cryptography, data protection, secure coding practices, input validation, security testing,
code review, and vulnerability management. This original study bank targets application and analysis skills for the WGU D487 Objective
Assessment, with full rationales for every answer. For review use only; not an institutional proctored assessment.




PASSING SCORE LEVEL FORMAT
80% Advanced (Secure Software Design) Application / Analysis


STUVIA ACTUAL EXAM Page 1

, SECTION 1: Secure Design Principles & Architecture


Q1. A development team is designing a payment microservice that must handle cardholder data. The architect requires least privilege.
A junior engineer proposes granting the service account full write access to the entire customer database for future flexibility.
Which response best applies secure design principles?

A. Reject and require only the minimum permissions needed for current payment operations.
B. Approve because future-proofing reduces technical debt.
C. Approve write access but add network isolation as compensation.
D. Grant full access in development and restrict only in production.
Correct Answer: A
Rationale: Least privilege grants only permissions necessary for the current function. Broad write access expands the attack surface. Future needs belong in
controlled change management, not preemptive over-privileging.


Q2. An organization migrates a monolithic application to microservices. The security architect must define trust boundaries. Which
design decision most effectively establishes clear trust boundaries between services?

A. Allow all services to share a single mutual TLS certificate.
B. Place all microservices in the same Kubernetes namespace and rely on network policies alone.
C. Implement mutual authentication and authorization at each service interface, treating every call as potentially untrusted.
D. Use a shared in-memory cache for session data across all services.
Correct Answer: C
Rationale: Treating each inter-service call as untrusted and enforcing mutual authentication plus authorization creates explicit trust boundaries. Shared
certificates or caches can collapse boundaries and increase lateral movement risk.


Q3. A design review finds that a web application stores session tokens in local storage and transmits them via URL query parameters.
Which secure design principle is most directly violated, and what is the preferred remediation?

A. Fail-secure defaults; switch to HTTP-only secure cookies and avoid placing tokens in URLs.
B. Economy of mechanism; keep the approach but shorten token lifetime to 5 minutes.
C. Complete mediation; add client-side JavaScript validation of token format.
D. Open design; publish the token format for researcher review.
Correct Answer: A
Rationale: Local storage exposes tokens to XSS; URLs risk leakage via logs and referrers. HTTP-only, Secure, SameSite cookies protect tokens from script
access and accidental exposure.


Q4. During architecture evaluation for a healthcare records system, the team debates defense-in-depth versus relying solely on a
strong perimeter firewall and WAF. Which argument best supports defense-in-depth?

A. Perimeter controls suffice if the WAF signature database is updated daily.
B. If any single control fails, additional layers can still prevent or limit compromise of protected health information.
C. Defense-in-depth increases latency and should be avoided for medical systems.
D. Regulatory frameworks prohibit layered controls because they complicate audit trails.
Correct Answer: B
Rationale: Defense-in-depth assumes individual controls can fail. Multiple independent layers reduce the probability that a single failure leads to full
compromise of sensitive health data.




STUVIA ACTUAL EXAM · Page 2

, SECTION 1: Secure Design Principles & Architecture


Q5. A design team applies separation of duties to a financial transaction workflow. Currently one administrative role can both create a
payment instruction and authorize its release. Which architectural change best enforces separation of duties?

A. Split create and authorize into distinct roles that cannot be held by the same principal, enforced at the authorization service.
B. Require two-factor authentication for the same administrative role.
C. Add an email notification to a manager after the same user performs both actions.
D. Log both actions with high-severity alerts but leave the role model unchanged.
Correct Answer: A
Rationale: True separation of duties requires that no single principal can perform both conflicting functions. Distinct roles enforced by the authorization layer
prevent collusion or abuse by one actor.


Q6. An architect evaluates a zero-trust network model for a cloud-native application spanning multiple availability zones. Which
characteristic is most essential to a zero-trust design?

A. Implicit trust for any traffic originating inside the corporate VPC.
B. Reliance on a single strong perimeter VPN that all users must traverse.
C. Continuous verification of identity and device posture for every request, regardless of network location.
D. Disabling encryption for east-west traffic to improve inspection performance.
Correct Answer: C
Rationale: Zero-trust assumes no implicit trust based on network location. Every request must be authenticated, authorized, and evaluated against current
identity and device context.


Q7. A product owner requests that public API error messages include full stack traces and database query details for external
integrators. How should the security architect respond using secure design principles?

A. Approve because transparency improves developer experience and satisfies open-design.
B. Include stack traces but encrypt them with a shared partner key.
C. Allow stack traces only for authenticated partners.
D. Reject detailed internal error information in public responses; return generic error codes and log detailed diagnostics server-side
only.
Correct Answer: D
Rationale: Detailed errors can reveal implementation details useful to attackers. Secure design favors generic public messages and detailed server-side
logging.


Q8. When applying complete mediation to an object-capability system, which design choice most strongly supports the principle?

A. Cache authorization decisions for 24 hours to reduce policy-engine load.
B. Check the capability or authorization token on every access to a protected resource, without relying solely on prior checks.
C. Perform authorization only at login and issue a long-lived bearer token.
D. Delegate all mediation to the client application.
Correct Answer: B
Rationale: Complete mediation requires that every access to a protected object is checked. Long caches or login-only checks can allow unauthorized acces
if privileges change or tokens are stolen.


Q9. A team designs an API gateway that will enforce rate limiting, authentication, and request validation. A developer suggests
implementing these controls only inside each backend microservice. Which architectural concern most strongly argues against
that suggestion?

A. Duplicating identical controls in every service increases the chance of inconsistent enforcement and missed updates.
B. API gateways are inherently untrusted and should never enforce security policy.
C. Rate limiting at the gateway always causes false positives.
D. Microservices cannot implement authentication because they lack network visibility.
Correct Answer: A
Rationale: Centralizing common security controls at the gateway provides consistent enforcement and simplifies updates. Scattering identical logic raises th
risk that one service will omit or misconfigure a control.




STUVIA ACTUAL EXAM · Page 3

, Q10. A design review notes that the system uses a single shared symmetric key for encrypting all customer records across multiple
tenants. Which design principle is most clearly violated, and what is the preferred remediation?

A. Least common mechanism; switch to per-tenant keys managed through a key hierarchy.
B. Open design; publish the key-rotation schedule publicly.
C. Psychological acceptability; keep the single key to reduce operator complexity.
D. Fail-safe defaults; disable encryption if key management becomes complex.
Correct Answer: A
Rationale: A single shared key across tenants creates a high-value target and violates isolation. Per-tenant keys limit the blast radius of key compromise.


Q11. An organization adopts secure-by-default configuration for cloud workloads. A platform engineer proposes leaving SSH port 22
open to the world on bastion hosts for emergency access. How should the security architect respond?

A. Accept the proposal; emergency access takes precedence.
B. Permit the open port only in non-production accounts.
C. Allow the open port but require a strong 20-character root password.
D. Reject and require that administrative access use a just-in-time, identity-aware proxy with no permanent public exposure of
management ports.
Correct Answer: D
Rationale: Secure-by-default means systems start locked-down. Permanent public exposure of management ports violates this. Just-in-time identity-aware
access provides emergency capability without continuous attack surface.


Q12. A design document claims the system achieves security through obscurity by using non-standard ports and custom protocol
headers. Which statement best evaluates this claim?

A. Obscurity is a valid primary control and should be the first line of defense.
B. Obscurity may provide limited secondary benefit but must never be relied upon as a primary security control; open design and
robust mechanisms are required.
C. Custom protocols automatically satisfy open-design because the source is internal.
D. Non-standard ports eliminate the need for authentication.
Correct Answer: B
Rationale: Kerckhoffs's principle and open-design state that security should not depend on secrecy of the design. Obscurity is insufficient as a primary
control.


Q13. When designing a multi-tenant SaaS platform, which approach most closely aligns with strong secure design principles for
isolation?

A. Combine database-level row security, separate encryption keys per tenant, and network isolation of tenant workloads where
feasible.
B. Rely solely on application-layer filters that add a tenant_id WHERE clause to every query.
C. Store all tenants in a single shared schema and trust developers to remember the tenant filter.
D. Use a single global administrator account that can access any tenant.
Correct Answer: A
Rationale: Defense-in-depth isolation uses multiple independent mechanisms. Application-only filters are fragile; a single missed filter can leak data across
tenants.


Q14. A team applies economy of mechanism while designing an authentication module. Which decision best reflects that principle?
A. Implement five different authentication protocols so users can choose any method.
B. Write a proprietary authentication algorithm from scratch.
C. Select a single, well-understood, standardized authentication protocol and avoid unnecessary custom extensions.
D. Embed authentication logic deeply into business code.
Correct Answer: C
Rationale: Economy of mechanism favors simple, well-understood designs. A single standardized protocol reduces attack surface and review complexity.




STUVIA ACTUAL EXAM · Page 4

Document information

Uploaded on
September 25, 2026
Number of pages
38
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$16.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
STUVIAACTUALEXAMS
3.5
(179)
Sold
1349
Followers
210
Items
10317
Last sold
1 day ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions