WGU D487 SECURE SW DESIGN EXAM
2026 ACTUAL EXAM 2 VERSIONS
(VERSION A AND B) COMPLETE ACCURATE EXAM QUESTIONS
WITH DETAILED VERIFIED ANSWERS (100% CORRECT
ANSWERS) / ALREADY GRADED A+
VERSION A
1.A software project is nearing the final stage of its lifecycle, and the
development team is planning the secure and complete removal of the
application from all systems. In which phase of the SDLC does this activity
occur?
A) Design phase
B) Implementation phase
C) Testing phase
D) End of life phase
Correct Answer: D) End of life phase
Rationale: The end-of-life phase occurs when software is being retired and
removed from the environment. Activities include securely decommissioning
the application, removing it from systems and infrastructure, revoking
associated access, and properly disposing of or archiving relevant data. The
design, testing, and implementation phases occur earlier in the SDLC and focus
on building, validating, and deploying the software rather than retiring it.
,2.A cybersecurity team is analyzing potential security risks for a web
application by identifying vulnerabilities and considering possible attack
scenarios. What is this structured process called?
A) Implementation phase
B) Testing phase
C) Security development life cycle (SDL)
D) Threat modeling
Correct Answer: D) Threat modeling
Rationale: Threat modeling is a structured process for identifying potential
threats, vulnerabilities, attack paths, and security risks in an application. It
allows developers and security teams to anticipate how an application could be
attacked and determine appropriate controls to mitigate those risks.
3.After all development is complete, a software application is pushed out to the
production environment, where users can access it. Which SDLC phase does
this activity represent?
A) Requirement phase
B) Deployment phase
C) Design phase
D) Maintenance phase
Correct Answer: B) Deployment phase
Rationale: The deployment phase involves moving completed and tested
software into the production environment so that it can be used by its intended
users. This occurs after development and testing and before the ongoing
maintenance activities that support the application during its operational life.
,4.An organization adopts a formalized approach to security, embedding best
practices throughout the software development process to ensure secure
applications. What is this structured approach known as?
A) Maintenance phase
B) Security Development Life Cycle (SDL)
C) Software Development Life Cycle (SDLC)
D) Threat modeling
Correct Answer: B) Security Development Life Cycle (SDL)
Rationale: The Security Development Life Cycle (SDL) is a structured
approach that integrates security practices and activities throughout the software
development process. It helps organizations identify and address security
requirements, threats, vulnerabilities, and
risks during development rather than treating security as an afterthought.
5.A software engineer is focused on the physical components, such as servers
and network devices, that support the new software application. What term
refers to these physical components?
A) Threat modeling
B) Secure code
C) Software
D) Hardware
Correct Answer: D) Hardware
Rationale: Hardware refers to the physical components of a computing
environment, including servers, network devices, storage systems, and other
tangible equipment. Software, by contrast, consists of programs and instructions
that run on the hardware.
, 6.A team is finalizing the technical design, considering how each requirement
will be implemented in the software. Which SDLC phase involves preparing
technical requirements for the software's design?
A) Design phase
B) Requirement phase
C) Maintenance phase
D) Testing phase
Correct Answer: A) Design phase
Rationale: The design phase translates requirements into a technical blueprint
for the software. It determines how the system will be structured and how its
functional and security requirements will be implemented. This includes
architecture, components, interfaces, data structures, and other technical
specifications.
7.A new software application is deployed, and the company establishes a
program to continuously monitor for security issues and updates. Which SDLC
phase encompasses this ongoing monitoring?
A) End of life phase
B) Testing phase
C) Maintenance phase
D) Planning phase
Correct Answer: C) Maintenance phase
Rationale: The maintenance phase occurs after deployment and involves
keeping the software operational, secure, and up to date. Activities can include
monitoring for security issues, applying patches and updates, fixing defects, and
addressing newly discovered vulnerabilities.
2026 ACTUAL EXAM 2 VERSIONS
(VERSION A AND B) COMPLETE ACCURATE EXAM QUESTIONS
WITH DETAILED VERIFIED ANSWERS (100% CORRECT
ANSWERS) / ALREADY GRADED A+
VERSION A
1.A software project is nearing the final stage of its lifecycle, and the
development team is planning the secure and complete removal of the
application from all systems. In which phase of the SDLC does this activity
occur?
A) Design phase
B) Implementation phase
C) Testing phase
D) End of life phase
Correct Answer: D) End of life phase
Rationale: The end-of-life phase occurs when software is being retired and
removed from the environment. Activities include securely decommissioning
the application, removing it from systems and infrastructure, revoking
associated access, and properly disposing of or archiving relevant data. The
design, testing, and implementation phases occur earlier in the SDLC and focus
on building, validating, and deploying the software rather than retiring it.
,2.A cybersecurity team is analyzing potential security risks for a web
application by identifying vulnerabilities and considering possible attack
scenarios. What is this structured process called?
A) Implementation phase
B) Testing phase
C) Security development life cycle (SDL)
D) Threat modeling
Correct Answer: D) Threat modeling
Rationale: Threat modeling is a structured process for identifying potential
threats, vulnerabilities, attack paths, and security risks in an application. It
allows developers and security teams to anticipate how an application could be
attacked and determine appropriate controls to mitigate those risks.
3.After all development is complete, a software application is pushed out to the
production environment, where users can access it. Which SDLC phase does
this activity represent?
A) Requirement phase
B) Deployment phase
C) Design phase
D) Maintenance phase
Correct Answer: B) Deployment phase
Rationale: The deployment phase involves moving completed and tested
software into the production environment so that it can be used by its intended
users. This occurs after development and testing and before the ongoing
maintenance activities that support the application during its operational life.
,4.An organization adopts a formalized approach to security, embedding best
practices throughout the software development process to ensure secure
applications. What is this structured approach known as?
A) Maintenance phase
B) Security Development Life Cycle (SDL)
C) Software Development Life Cycle (SDLC)
D) Threat modeling
Correct Answer: B) Security Development Life Cycle (SDL)
Rationale: The Security Development Life Cycle (SDL) is a structured
approach that integrates security practices and activities throughout the software
development process. It helps organizations identify and address security
requirements, threats, vulnerabilities, and
risks during development rather than treating security as an afterthought.
5.A software engineer is focused on the physical components, such as servers
and network devices, that support the new software application. What term
refers to these physical components?
A) Threat modeling
B) Secure code
C) Software
D) Hardware
Correct Answer: D) Hardware
Rationale: Hardware refers to the physical components of a computing
environment, including servers, network devices, storage systems, and other
tangible equipment. Software, by contrast, consists of programs and instructions
that run on the hardware.
, 6.A team is finalizing the technical design, considering how each requirement
will be implemented in the software. Which SDLC phase involves preparing
technical requirements for the software's design?
A) Design phase
B) Requirement phase
C) Maintenance phase
D) Testing phase
Correct Answer: A) Design phase
Rationale: The design phase translates requirements into a technical blueprint
for the software. It determines how the system will be structured and how its
functional and security requirements will be implemented. This includes
architecture, components, interfaces, data structures, and other technical
specifications.
7.A new software application is deployed, and the company establishes a
program to continuously monitor for security issues and updates. Which SDLC
phase encompasses this ongoing monitoring?
A) End of life phase
B) Testing phase
C) Maintenance phase
D) Planning phase
Correct Answer: C) Maintenance phase
Rationale: The maintenance phase occurs after deployment and involves
keeping the software operational, secure, and up to date. Activities can include
monitoring for security issues, applying patches and updates, fixing defects, and
addressing newly discovered vulnerabilities.