WGU PRE D320: Questions & Correct Answers
Which Open Web Application Security Project (OWASP) Top 10 vulnerability
category did their training cover?
Vulnerable and outdated components
Identification and authentication failures
Broken access control
Security logging failures Right Ans - Broken access control
An organization's engineers recently attended a training session that raised
their awareness of the dangers of using weak algorithms or protocols for data
security.
Which Open Web Application Security Project (OWASP) Top 10 vulnerability
category did their training cover?
Insecure design
Hashing
Sandboxing
Cryptographic failures Right Ans - Cryptographic failures
A company plans to deploy a new application. Before the deployment, the
company hires an IT security consultant to perform a zero-knowledge test to
access the application as an external hacker would.
Which testing technique applies to the work the consultant is performing?
Black box
White box
Abuse case
Static application Right Ans - Black box
Which concept refers to multiple teams and roles within an organization that
perform testing on code from end to end to ensure that the code meets all
standards and requirements?
Quality assurance
Identity assurance
Full tests
Tabletop tests Right Ans - Quality assurance
,What is the purpose of implementing rate limiting in application
programming interface (API) security?
To reduce API response time
To block unauthorized API access
To prevent API overuse
To increase API usage Right Ans - To prevent API overuse
An organization wants to ensure that untested software updates provided by
a third-party vendor are not run in its mission-critical environment.
What should the organization use in this scenario?
Automatic updates
Update notifications
Update documentation
Manual updates Right Ans - Manual updates
Which software development methodology is sequential, with each phase
followed by the next phase and with no overlap between the phases?
Scrum
Lean
Agile
Waterfall Right Ans - Waterfall
Which phase of software design includes gathering customer input to
determine a system's desired functionality?
Ongoing operations
Decommissioning
Planning
Requirements definition Right Ans - Requirements definition
Which technology is used to prevent cross-site request forgery (CSRF)
attacks?
Encoding
Tokens
, Multifactor authentication (MFA)
Identity-based encryption (IBE) Right Ans - Tokens
A project manager is working on a new software project for a customer. The
project manager works closely with the customer to get input on the desired
features and ranks them based on how critical they are for the project.
Which phase of the software development life cycle (SDLC) is the project
manager working on?
Planning
Requirements definition
Development
Ongoing operations Right Ans - Requirements definition
Which web application firewall (WAF) feature protects the application servers
behind it from systems sending requests?
Reverse proxy
User-based filters
Content-based filters
Reverse IP lookup Right Ans - Reverse proxy
Which scheme would provide protection if an entire physical solid-state drive
was lost or stolen?
File-level encryption
Transport Layer Security (TLS)
Secure Socket Layer (SSL)
Full-disk encryption Right Ans - Full-disk encryption
A small organization adopts a strategy to ensure that the cryptographic keys it
uses in its cloud environment are securely stored and handled.
Which third-party service should the organization leverage for key
administration in the given scenario?
Hardware security module (HSM)
Cloud access security broker (CASB)
Identity provider (IdP)
Which Open Web Application Security Project (OWASP) Top 10 vulnerability
category did their training cover?
Vulnerable and outdated components
Identification and authentication failures
Broken access control
Security logging failures Right Ans - Broken access control
An organization's engineers recently attended a training session that raised
their awareness of the dangers of using weak algorithms or protocols for data
security.
Which Open Web Application Security Project (OWASP) Top 10 vulnerability
category did their training cover?
Insecure design
Hashing
Sandboxing
Cryptographic failures Right Ans - Cryptographic failures
A company plans to deploy a new application. Before the deployment, the
company hires an IT security consultant to perform a zero-knowledge test to
access the application as an external hacker would.
Which testing technique applies to the work the consultant is performing?
Black box
White box
Abuse case
Static application Right Ans - Black box
Which concept refers to multiple teams and roles within an organization that
perform testing on code from end to end to ensure that the code meets all
standards and requirements?
Quality assurance
Identity assurance
Full tests
Tabletop tests Right Ans - Quality assurance
,What is the purpose of implementing rate limiting in application
programming interface (API) security?
To reduce API response time
To block unauthorized API access
To prevent API overuse
To increase API usage Right Ans - To prevent API overuse
An organization wants to ensure that untested software updates provided by
a third-party vendor are not run in its mission-critical environment.
What should the organization use in this scenario?
Automatic updates
Update notifications
Update documentation
Manual updates Right Ans - Manual updates
Which software development methodology is sequential, with each phase
followed by the next phase and with no overlap between the phases?
Scrum
Lean
Agile
Waterfall Right Ans - Waterfall
Which phase of software design includes gathering customer input to
determine a system's desired functionality?
Ongoing operations
Decommissioning
Planning
Requirements definition Right Ans - Requirements definition
Which technology is used to prevent cross-site request forgery (CSRF)
attacks?
Encoding
Tokens
, Multifactor authentication (MFA)
Identity-based encryption (IBE) Right Ans - Tokens
A project manager is working on a new software project for a customer. The
project manager works closely with the customer to get input on the desired
features and ranks them based on how critical they are for the project.
Which phase of the software development life cycle (SDLC) is the project
manager working on?
Planning
Requirements definition
Development
Ongoing operations Right Ans - Requirements definition
Which web application firewall (WAF) feature protects the application servers
behind it from systems sending requests?
Reverse proxy
User-based filters
Content-based filters
Reverse IP lookup Right Ans - Reverse proxy
Which scheme would provide protection if an entire physical solid-state drive
was lost or stolen?
File-level encryption
Transport Layer Security (TLS)
Secure Socket Layer (SSL)
Full-disk encryption Right Ans - Full-disk encryption
A small organization adopts a strategy to ensure that the cryptographic keys it
uses in its cloud environment are securely stored and handled.
Which third-party service should the organization leverage for key
administration in the given scenario?
Hardware security module (HSM)
Cloud access security broker (CASB)
Identity provider (IdP)