• Wrong document? Swap it for free
  • Written by students who passed
  • Immediately available after payment
  • Read online or as PDF
Sell
Where do you study
Your language
Document preview thumbnail
Preview 4 out of 75 pages
Exam (elaborations)

WGU D487 Secure Software Design Exam – 250 Questions with Answers & Explanations | Latest 2026 Objective Assessment Prep Guide

Document preview thumbnail
Preview 4 out of 75 pages

Comprehensive WGU D487 exam-preparation resource covering secure software development throughout the SDLC, including security requirements and risk assessment, threat modeling, Defense in Depth, secure architecture, security testing, secure coding practices, Agile and DevSecOps, privacy, and software security processes. Designed for 2026 Objective Assessment preparation and conceptual review.

Content preview

WGU D487 Secure Software Design Exam – 250
Questions with Answers & Explanations | Latest 2026
Objective Assessment Prep Guide

description


WGU D487 Secure Software Design Exam – Latest 2026 prep with 250 multiple-choice
questions, verified answers, and detailed explanations. Covers secure design principles,
STRIDE/DREAD/PASTA threat modeling, OWASP Top 10, secure coding, authentication,
authorization, cryptography, security architecture, vulnerability assessment, and
DevSecOps. Perfect for WGU Objective Assessment and guaranteed pass. Instant PDF
download.




SECTION 1: SECURE DESIGN PRINCIPLES (Questions 1–35)

1. A hospital information system allows nurses to view patient records but also
grants them access to the billing modification module. An audit reveals nurses have
never needed to modify billing records. Which principle is violated?
A. Defense in depth
B. Principle of least privilege
C. Economy of mechanism
D. Open design

,Answer: B. The principle of least privilege mandates that subjects receive only the minimum
access necessary to perform their tasks. Nurses who never modify billing records should
not have billing modification access .

2. A system grants access during a directory server failure so users are not locked
out. Which principle requires the system to deny access instead?
A. Principle of least privilege
B. Complete mediation
C. Fail-safe defaults
D. Separation of privilege

Answer: C. Fail-safe defaults dictate that the default access decision must be denial when a
system cannot determine correct permissions. Granting access during failure violates this
principle .

3. A team chooses a well-vetted TLS implementation with three steps over a custom
cryptographic protocol with twelve interdependent steps. Which principle supports
this?
A. Economy of mechanism
B. Defense in breadth
C. Psychological acceptability
D. Open design

Answer: A. Economy of mechanism favors simpler designs over complex ones because
simpler designs are easier to verify, test, and maintain securely .

4. An e-commerce platform relies solely on a perimeter firewall. After a breach, the
team adds a WAF, input validation, and encrypted database connections. Which
principle does this illustrate?

,A. Fail-safe defaults
B. Least common mechanism
C. Defense in depth
D. Psychological acceptability

Answer: C. Defense in depth uses multiple overlapping security controls so that if one layer
fails, additional layers continue to provide protection .

5. Which principle ensures that access is checked every time a subject requests a
resource, rather than relying on cached permissions?
A. Complete mediation
B. Fail-safe defaults
C. Separation of duties
D. Least privilege

Answer: A. Complete mediation requires that every access attempt to every object be
checked for authorization, preventing stale permissions from being exploited .

6. Which principle requires that a security mechanism should not depend on the
secrecy of its design or implementation?
A. Open design
B. Economy of mechanism
C. Least common mechanism
D. Fail-safe defaults

Answer: A. Open design states that security should not rely on secrecy of design. The
security should depend on the key, not the algorithm .

7. A developer embeds a hardcoded password in source code for database access.
Which principle is violated?

, A. Defense in depth
B. Least privilege
C. Fail-safe defaults
D. Secure defaults

Answer: B. Hardcoded credentials violate least privilege because any user with access to
the code can potentially access the database with full credentials .

8. What does the "IAAA" security framework stand for?
A. Identity, Authentication, Authorization, Accounting
B. Integrity, Availability, Authentication, Auditing
C. Identity, Access, Authorization, Auditing
D. Integrity, Authentication, Authorization, Availability

Answer: A. IAAA stands for Identification, Authentication, Authorization, and Accounting. It
describes the process of verifying identity, granting permissions, and tracking actions .

9. A security architect separates administrative duties so no single person can
deploy to production without review. Which principle is applied?
A. Least privilege
B. Separation of duties
C. Defense in depth
D. Fail-safe defaults

Answer: B. Separation of duties ensures that no single person has complete control over a
critical function, reducing insider threat and error risk .

10. The "Attack Surface" refers to:
A. The total number of vulnerabilities in an application
B. The sum of all points where an attacker can try to enter or extract data

Document information

Uploaded on
September 29, 2026
Number of pages
75
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$35.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Sold
4
Followers
1
Items
222
Last sold
1 week ago




Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions