Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 143 pages
Exam (elaborations)

WGU MASTER'S COURSE C706 - SECURE SOFTWARE DESIGN EXAM LATEST 2024 ACTUAL EXAM 400 QUESTIONS AND CORRECT DETAILED ANSWERS WITH RATIONALES (VERIFIED ANSWERS) |ALREADY GRADED A+

Document preview thumbnail
Preview 4 out of 143 pages

WGU MASTER'S COURSE C706 - SECURE SOFTWARE DESIGN EXAM LATEST 2024 ACTUAL EXAM 400 QUESTIONS AND CORRECT DETAILED ANSWERS WITH RATIONALES (VERIFIED ANSWERS) |ALREADY GRADED A+

Content preview

WGU MASTER'S COURSE C706 - SECURE SOFTWARE
DESIGN EXAM LATEST 2024 ACTUAL EXAM 400
QUESTIONS
AND CORRECT DETAILED ANSWERS WITH RATIONALES
(VERIFIED ANSWERS) |ALREADY GRADED A+
What is the National Vulnerability Database?

The NVD takes CVEs as input and builds upon the information included in the CVE entries to provide
enhanced information for each CVE Identifier, such as fix information, severity scores, and impact
ratings. NVD also provides advanced searching features such as by individual CVE-ID; by OS; by vendor
name, product name, and/or version number; and by vulnerability type, severity, related exploit
range, and impact.




What are the key factors in security Assessment regarding secure software?

a. Accuracy of planned Security Development Life Cycle (SDL) activities



i. All SDL activities are accurately identified



b. Product risk profile



i. Management understands the true cost of developing the product



c. Accuracy of threat profile



i. Mitigating steps and countermeasures are in place for the product to be successful in its
environment.



d. Coverage of relevant regulations, certifications, and compliance frameworks



i. All applicable legal and compliance aspects are covered.

, WGU MASTER'S COURSE C706 - SECURE SOFTWARE
DESIGN EXAM LATEST 2024 ACTUAL EXAM 400
QUESTIONS
AND CORRECT DETAILED ANSWERS WITH RATIONALES
(VERIFIED ANSWERS) |ALREADY GRADED A+
e. Coverage of security objectives needed for software



“Must have” security objectives are met.




Why are data flow documents (DFD) an important analytical tool?

DFDs allow you to visualize the data flow through software, decompose the software architecture,
and focus on specific processes involved in processing specific data.




Explain the Generic Risk Model.

The General Risk Model is a more subjective model that uses the formula "Risk = Likelihood x Impact"
to represent a threat mathematically.

i. With the General Risk Model, likelihood is defined by the ease of exploitation and the
possibility of realizing a threat.

ii. Impact is defined by the damage potential and the extent of the impact




Explain the TRIKE Model.

TRIKE is a unique, open-source threat modeling process focused on satisfying the security auditing
process from a cyber risk management perspective. The foundation of the Trike threat modeling
methodology is a "requirements model." The requirements model ensures the assigned level of risk
for each asset is "acceptable" to the various stakeholders.

, WGU MASTER'S COURSE C706 - SECURE SOFTWARE
DESIGN EXAM LATEST 2024 ACTUAL EXAM 400
QUESTIONS
AND CORRECT DETAILED ANSWERS WITH RATIONALES
(VERIFIED ANSWERS) |ALREADY GRADED A+
How do you mitigate STRIDE spoofing and what security principle does it affect?

Authentication. Implement secure user authentication methods, including both secure password
requirements and multi-factor authentication (MFA).




How do you mitigate STRIDE Tampering and what security principle does it affect?

Integrity. The application should be designed to validate user inputs, and encode outputs. Static code
analysis should be used to identify vulnerabilities to tampering in the application both during the
development stage and once the application is in production.




How do you mitigate STRIDE Repudiation and what security principle does it affect?

Non-Repudiation. incorporating digital signatures in the application that provide proof of actions, or
ensuring that full, tamper-proof logs are in place.




How do you mitigate STRIDE Info Disclosure and what security principle does it affect?

Confidentiality. Error messages, response headers, and background information should be as generic
as possible to avoid revealing clues about the application's behavior.

Proper access controls and authorizations should be in place to prevent unauthorized access to
information. The application itself should be checked over from a user perspective to validate that
developer comments and other information are not revealed in the production environment.




How do you mitigate STRIDE Denial of Service and what security principle does it affect?

Availability. Configuring firewalls to block traffic from certain sources such as reserved, loopback, or
private IP addresses, or unassigned DCHPDHCP clients, or introducing rate limiting to manage traffic

, WGU MASTER'S COURSE C706 - SECURE SOFTWARE
DESIGN EXAM LATEST 2024 ACTUAL EXAM 400
QUESTIONS
AND CORRECT DETAILED ANSWERS WITH RATIONALES
(VERIFIED ANSWERS) |ALREADY GRADED A+


How do you mitigate STRIDE Elevation of Privilege and what security principle does it affect?

Authorization. includes managing the identity lifecycle, enforcing the principle of least privilege for all
users, hardening systems and applications through configuration changes, removing unnecessary
rights and access, closing ports




What are some common defects software testing should look for?

a. XSS

b. SQL Injection

c. Errors with applications

d. Patch errors

e. Buffer overflow

f. Memory leaks

g. Assertion failures

h. Error handling




What types of tools are these?

a. AppScan by IBM

b. GFI Languard by GFI

c. Hailstorm by Cenzic

d. McAfee Vulnerability Manager (MVM) by McAfee

e. Nessus by Tenable Network Security

Document information

Uploaded on
November 12, 2024
Number of pages
143
Written in
2024/2025
Type
Exam (elaborations)
Contains
Questions & answers
$18.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
Creativepdf
3.8
(5)
Sold
38
Followers
28
Items
2597
Last sold
5 months ago


Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions