W
DEGSU NrA
IGM EXSTAEMR'LSACTOEU
STRS2E02C470A6CT-rU
SEACLUERXEAM
SO4F0TW AU
0rQ R ESTIONS
WGU MASTER'S COURSE C706 - r r r r
SECURE SOFTWARE DESIGN EXAM LATEST 2024 ACTUAL EXA
r r r r r r r r
M400 QUESTIONSAND CORRECT DETAILED ANSWERS WITH
r r r r r r r r
RATIONALES (VERIFIED ANSWERS) | GRADED A+ r r r r r
Whatrisrarsteprforrconstructingrarthreatrmodelrforrarprojectrwhenrusingrpracticalrriskranalysis?
ArAlignryourrbusinessrgoals
BrApplyrengineeringrmethods
CrEstimaterprobabilityrofrprojectrtime
DrMakerarlistrofrwhatryourarertryingrtorprotectr-rANSWER-D
Whichrcyberrthreatsrarertypicallyrsurgicalrbyrnature,rhaverhighlyrspecificrtargeting,randrarertechnologicallyr
sophisticated?
ArTacticalrattacksr
BrCriminalrattacksr
CrStrategicrattacks
DrUser-specificrattacksr-rANSWER-A
Whichrtyperofrcyberattacksrareroftenrintendedrtorelevaterawarenessrofrartopic?
Ar Cyberwarfarer
BrTacticalrattacks
CrUser-specificrattacks
DrSociopoliticalrattacksr-rANSWER-D
Whatrtyperofrattackrlocksraruser'srdesktoprandrthenrrequiresrarpaymentrtorunlockrit?
,W
DEGSU NrA
IGM EXSTAEMR'LSACTOEU
STRS2E02C470A6CT-rU
SEACLUERXEAM
SO4F0TW AU
0rQ R ESTIONS
ArPhishing
,W
DEGSU NrA
IGM EXSTAEMR'LSACTOEU
STRS2E02C470A6CT-rU
SEACLUERXEAM
SO4F0TW AU
0rQ R ESTIONS
BrKeylogger
CrRansomware
DrDenial-of-servicer-rANSWER-C
WhatrisrarcountermeasureragainstrvariousrformsrofrXMLrandrXMLrpathrinjectionrattacks?
ArXMLrnamer wrappingrB
XMLrunicoderencoding
r
CrXMLrattributerescaping
DrXMLrdistinguishedrnamerescapingr-rANSWER-C
WhichrcountermeasurerisrusedrtormitigaterSQLrinjectionrattacks?
ArSQLrFirewall
BrProjectedrbijection
CrQueryrparameterization
DrProgressiverColdFusionr-rANSWER-C
Whatrisranrappropriatercountermeasurertoranrescalationrofrprivilegerattack?
ArEnforcingrstrongrpasswordrpolicies
BrUsingrstandardrencryptionralgorithmsrandrcorrectrkeyrsizes
CrEnablingrtherauditingrandrloggingrofrallradministrationractivities
DrRestrictingraccessrtorspecificroperationsrthroughrrole-basedraccessrcontrolsr-rANSWER-D
, W
DEGSU NrA
IGM EXSTAEMR'LSACTOEU
STRS2E02C470A6CT-rU
SEACLUERXEAM
SO4F0TW AU
0rQ R ESTIONS
Whichrconfigurationrmanagementrsecurityrcountermeasurerimplementsrleastrprivilegeraccessrcontrol?
ArFollowingrstrongrpasswordrpoliciesrtorrestrictraccess
BrRestrictingrfileraccessrtorusersrbasedronrauthorization
CrAvoidingrclearrtextrformatrforrcredentialsrandrsensitiverdata
DrUsingrAESr256rencryptionrforrcommunicationsrofrarsensitivernaturer-rANSWER-B
Whichrphaserofrthersoftwarerdevelopmentrlifercycler(SDL/SDLC)rwouldrberusedrtordeterminerthermini
mumrsetrofrprivilegesrrequiredrtorperformrthertargetedrtaskrandrrestrictrtheruserrtorardomainrwithrthos
erprivileges?
ArDesign
BrDeploy
CrDevelopment
DrImplementationr-rANSWER-A
Whichrleastrprivilegermethodrisrmorergranularrinrscoperandrgrantsrspecificrprocessesronlyrtherprivilege
srnecessaryrtorperformrcertainrrequiredrfunctions,rinsteadrofrgrantingrthemrunrestrictedraccessrtorthers
ystem?
ArEntitlementrprivilege
BrSeparationrofrprivilege
CrAggregationrofrprivileges
DrSegregationrofrresponsibilitiesr-rANSWER-B
Whyrdoesrprivilegercreeprposerarpotentialrsecurityrrisk?
DEGSU NrA
IGM EXSTAEMR'LSACTOEU
STRS2E02C470A6CT-rU
SEACLUERXEAM
SO4F0TW AU
0rQ R ESTIONS
WGU MASTER'S COURSE C706 - r r r r
SECURE SOFTWARE DESIGN EXAM LATEST 2024 ACTUAL EXA
r r r r r r r r
M400 QUESTIONSAND CORRECT DETAILED ANSWERS WITH
r r r r r r r r
RATIONALES (VERIFIED ANSWERS) | GRADED A+ r r r r r
Whatrisrarsteprforrconstructingrarthreatrmodelrforrarprojectrwhenrusingrpracticalrriskranalysis?
ArAlignryourrbusinessrgoals
BrApplyrengineeringrmethods
CrEstimaterprobabilityrofrprojectrtime
DrMakerarlistrofrwhatryourarertryingrtorprotectr-rANSWER-D
Whichrcyberrthreatsrarertypicallyrsurgicalrbyrnature,rhaverhighlyrspecificrtargeting,randrarertechnologicallyr
sophisticated?
ArTacticalrattacksr
BrCriminalrattacksr
CrStrategicrattacks
DrUser-specificrattacksr-rANSWER-A
Whichrtyperofrcyberattacksrareroftenrintendedrtorelevaterawarenessrofrartopic?
Ar Cyberwarfarer
BrTacticalrattacks
CrUser-specificrattacks
DrSociopoliticalrattacksr-rANSWER-D
Whatrtyperofrattackrlocksraruser'srdesktoprandrthenrrequiresrarpaymentrtorunlockrit?
,W
DEGSU NrA
IGM EXSTAEMR'LSACTOEU
STRS2E02C470A6CT-rU
SEACLUERXEAM
SO4F0TW AU
0rQ R ESTIONS
ArPhishing
,W
DEGSU NrA
IGM EXSTAEMR'LSACTOEU
STRS2E02C470A6CT-rU
SEACLUERXEAM
SO4F0TW AU
0rQ R ESTIONS
BrKeylogger
CrRansomware
DrDenial-of-servicer-rANSWER-C
WhatrisrarcountermeasureragainstrvariousrformsrofrXMLrandrXMLrpathrinjectionrattacks?
ArXMLrnamer wrappingrB
XMLrunicoderencoding
r
CrXMLrattributerescaping
DrXMLrdistinguishedrnamerescapingr-rANSWER-C
WhichrcountermeasurerisrusedrtormitigaterSQLrinjectionrattacks?
ArSQLrFirewall
BrProjectedrbijection
CrQueryrparameterization
DrProgressiverColdFusionr-rANSWER-C
Whatrisranrappropriatercountermeasurertoranrescalationrofrprivilegerattack?
ArEnforcingrstrongrpasswordrpolicies
BrUsingrstandardrencryptionralgorithmsrandrcorrectrkeyrsizes
CrEnablingrtherauditingrandrloggingrofrallradministrationractivities
DrRestrictingraccessrtorspecificroperationsrthroughrrole-basedraccessrcontrolsr-rANSWER-D
, W
DEGSU NrA
IGM EXSTAEMR'LSACTOEU
STRS2E02C470A6CT-rU
SEACLUERXEAM
SO4F0TW AU
0rQ R ESTIONS
Whichrconfigurationrmanagementrsecurityrcountermeasurerimplementsrleastrprivilegeraccessrcontrol?
ArFollowingrstrongrpasswordrpoliciesrtorrestrictraccess
BrRestrictingrfileraccessrtorusersrbasedronrauthorization
CrAvoidingrclearrtextrformatrforrcredentialsrandrsensitiverdata
DrUsingrAESr256rencryptionrforrcommunicationsrofrarsensitivernaturer-rANSWER-B
Whichrphaserofrthersoftwarerdevelopmentrlifercycler(SDL/SDLC)rwouldrberusedrtordeterminerthermini
mumrsetrofrprivilegesrrequiredrtorperformrthertargetedrtaskrandrrestrictrtheruserrtorardomainrwithrthos
erprivileges?
ArDesign
BrDeploy
CrDevelopment
DrImplementationr-rANSWER-A
Whichrleastrprivilegermethodrisrmorergranularrinrscoperandrgrantsrspecificrprocessesronlyrtherprivilege
srnecessaryrtorperformrcertainrrequiredrfunctions,rinsteadrofrgrantingrthemrunrestrictedraccessrtorthers
ystem?
ArEntitlementrprivilege
BrSeparationrofrprivilege
CrAggregationrofrprivileges
DrSegregationrofrresponsibilitiesr-rANSWER-B
Whyrdoesrprivilegercreeprposerarpotentialrsecurityrrisk?