WGU Master's Course C706 - Secure Software Design
Study online at https://quizlet.com/_gun2xk
1. Which due diligence activity for supply chain security A
should occur in the initiation phase of the software
acquisition life cycle?
A Developing a request for proposal (RFP) that in-
cludes supply chain security risk management
B Lessening the risk of disseminating information dur-
ing disposal
C Facilitating knowledge transfer between suppliers
D Mitigating supply chain security risk by providing
user guidance
2. Which due diligence activity for supply chain security D
investigates the means by which data sets are shared
and assessed?
A on-site assessment
B process policy review
C third-party assessment
D document exchange and review
3. Consider these characteristics: B
-Identification of the entity making the access re-
quest
-Verification that the request has not changed since its
initiation
-Application of the appropriate authorization proce-
dures
-Reexamination of previously authorized requests by
the same entity
Which security design analysis is being described?
, WGU Master's Course C706 - Secure Software Design
Study online at https://quizlet.com/_gun2xk
A Open design
B Complete mediation
C Economy of mechanism
D Least common mechanism
4. Which software security principle guards against the B
improper modification or destruction of information
and ensures the nonrepudiation and authenticity of
information?
A Quality
B Integrity
C Availability
D Confidentiality
5. What type of functional security requirement involves C
receiving, processing, storing, transmitting, and deliv-
ering in report form?
A Logging
B Error handling
C Primary dataflow
D Access control flow
6. Which nonfunctional security requirement provides a A
way to capture information correctly and a way to
store that information to help support later audits?
A Logging
B Error handling
C Primary dataflow
D Access control flow
, WGU Master's Course C706 - Secure Software Design
Study online at https://quizlet.com/_gun2xk
7. Which security concept refers to the quality of in- D
formation that could cause harm or damage if dis-
closed?
A Isolation
B Discretion
C Seclusion
D Sensitivity
8. Which technology would be an example of an injection A
flaw, according to the OWASP Top 10?
A SQL
B API
C XML
D XSS
9. A company is creating a new software to track cus- D
tomer balance and wants to design a secure applica-
tion.
Which best practice should be applied?
A Develop a secure authentication method that has a
closed design
B Allow mediation bypass or suspension for software
testing and emergency planning
C Ensure there is physical acceptability to ensure soft-
ware is intuitive for the users to do their jobs
D Create multiple layers of protection so that a subse-
quent layer provides protection if a layer is breached
10. B
, WGU Master's Course C706 - Secure Software Design
Study online at https://quizlet.com/_gun2xk
A company is developing a secure software that has to
be evaluated and tested by a large number of experts.
Which security principle should be applied?
A Fail safe
B Open design
C Defense in depth
D Complete mediation
11. Which type of TCP scanning indicates that a system A
is moving to the second phase in a three-way TCP
handshake?
A TCP SYN scanning
B TCP ACK scanning
C TCP XMAS scanning
D TCP Connect scanning
12. Which evaluation technique provides invalid, unex- A
pected, or random data to the inputs of a computer
software program?
A Fuzz testing
B Static analysis
C Dynamic analysis
D Regression testing
13. Which approach provides an opportunity to improve D
the software development life cycle by tailoring the
process to the specific risks facing the organization?
A Agile methodology
Study online at https://quizlet.com/_gun2xk
1. Which due diligence activity for supply chain security A
should occur in the initiation phase of the software
acquisition life cycle?
A Developing a request for proposal (RFP) that in-
cludes supply chain security risk management
B Lessening the risk of disseminating information dur-
ing disposal
C Facilitating knowledge transfer between suppliers
D Mitigating supply chain security risk by providing
user guidance
2. Which due diligence activity for supply chain security D
investigates the means by which data sets are shared
and assessed?
A on-site assessment
B process policy review
C third-party assessment
D document exchange and review
3. Consider these characteristics: B
-Identification of the entity making the access re-
quest
-Verification that the request has not changed since its
initiation
-Application of the appropriate authorization proce-
dures
-Reexamination of previously authorized requests by
the same entity
Which security design analysis is being described?
, WGU Master's Course C706 - Secure Software Design
Study online at https://quizlet.com/_gun2xk
A Open design
B Complete mediation
C Economy of mechanism
D Least common mechanism
4. Which software security principle guards against the B
improper modification or destruction of information
and ensures the nonrepudiation and authenticity of
information?
A Quality
B Integrity
C Availability
D Confidentiality
5. What type of functional security requirement involves C
receiving, processing, storing, transmitting, and deliv-
ering in report form?
A Logging
B Error handling
C Primary dataflow
D Access control flow
6. Which nonfunctional security requirement provides a A
way to capture information correctly and a way to
store that information to help support later audits?
A Logging
B Error handling
C Primary dataflow
D Access control flow
, WGU Master's Course C706 - Secure Software Design
Study online at https://quizlet.com/_gun2xk
7. Which security concept refers to the quality of in- D
formation that could cause harm or damage if dis-
closed?
A Isolation
B Discretion
C Seclusion
D Sensitivity
8. Which technology would be an example of an injection A
flaw, according to the OWASP Top 10?
A SQL
B API
C XML
D XSS
9. A company is creating a new software to track cus- D
tomer balance and wants to design a secure applica-
tion.
Which best practice should be applied?
A Develop a secure authentication method that has a
closed design
B Allow mediation bypass or suspension for software
testing and emergency planning
C Ensure there is physical acceptability to ensure soft-
ware is intuitive for the users to do their jobs
D Create multiple layers of protection so that a subse-
quent layer provides protection if a layer is breached
10. B
, WGU Master's Course C706 - Secure Software Design
Study online at https://quizlet.com/_gun2xk
A company is developing a secure software that has to
be evaluated and tested by a large number of experts.
Which security principle should be applied?
A Fail safe
B Open design
C Defense in depth
D Complete mediation
11. Which type of TCP scanning indicates that a system A
is moving to the second phase in a three-way TCP
handshake?
A TCP SYN scanning
B TCP ACK scanning
C TCP XMAS scanning
D TCP Connect scanning
12. Which evaluation technique provides invalid, unex- A
pected, or random data to the inputs of a computer
software program?
A Fuzz testing
B Static analysis
C Dynamic analysis
D Regression testing
13. Which approach provides an opportunity to improve D
the software development life cycle by tailoring the
process to the specific risks facing the organization?
A Agile methodology