Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 3 out of 29 pages
Exam (elaborations)

Exam (elaborations) WGU D487 SECURE SW DESIGN

Document preview thumbnail
Preview 3 out of 29 pages

WGU D487 SECURE SW DESIGN MOST RECENT EXAM VERSION COMPLETE ACCURATE EXAM QUESTIONS WITH DETAILED VERIFIED ANSWERS (100% CORRECT ANSWERS) Within OpenSAMM, what focuses on the processes and activities related to organizational software development activities within OpenSAMM practice areas? - ANSWER Governance Which practice in the Ship (A5) phase of the security development cycle verifies whether the product meets security mandates? - ANSWER A5 policy compliance analysis Within OpenSAMM, what focuses on the processes and activities related to creating software within development projects within OpenSAMM practice areas? - ANSWER Construction Which practice in the Ship (A5) phase of the security development cycle uses tools to identify weaknesses in the product? - ANSWER Vulnerability scan Which post-release support activity should be completed when companies are joining together? - ANSWER Security architectural reviews Which of the Ship (A5) deliverables of the security development cycle are performed with A5 policy compliance analysis? - ANSWER analyze activities and standards Which of the Ship (A5) deliverables of the security development cycle are performed with code-assisted penetration testing? - ANSWER white-box security testing Which of the Ship (A5) deliverables of the security development cycle are performed with open-source licensing review? - ANSWER license compliance Which of the Ship (A5) deliverables of the security development cycle are performed with final security review? - ANSWER release and ship Which phase of penetration testing allows for remediation to be performed? - ANSWER deploy Which key deliverable occurs during post-release support? - ANSWER Third-party reviews Which business function of OpenSAMM is associated with the following core practices, governance? - ANSWER policy and compliance Which business function of OpenSAMM is associated with the following core practices, construction? - ANSWER threat assessment Which business function of OpenSAMM is associated with the following core practices, verification? - ANSWER code review Which business function of OpenSAMM is associated with the following core practices, deployment? - ANSWER vulnerability management What should the PIA include? - ANSWER summary of legislation, required process steps, technologies and techniques, and additional resources What is the primary task of the PIA process? - ANSWER to determine the need in the system, along with an initial definition of the problem to be solved. Which practice in the Ship (A5) phase of the security development cycle verifies whether the product meets security mandates? - ANSWER A5 policy compliance analysis Which post-release support activity defines the process to communicate, identify, and alleviate security threats? - ANSWER PRSA1: External vulnerability disclosure response Which post-release support activity defines the process to communicate, identify, and alleviate security threats? - ANSWER PRSA1: External vulnerability disclosure response What are two core practice areas of the OWASP Security Assurance Maturity Model (OpenSAMM)? - ANSWER Governance, Construction Which practice in the Ship (A5) phase of the security development cycle uses tools to identify weaknesses in the product? - ANSWER Vulnerability scan Which post-release support activity should be completed when companies are joining together? - ANSWER Security architectural reviews Which of the Ship (A5) deliverables of the security development cycle are performed during the A5 policy compliance analysis? - ANSWER Analyze activities and standards Which of the Ship (A5) deliverables of the security development cycle are performed during the code-assisted penetration testing? - ANSWER white-box security test Which of the Ship (A5) deliverables of the security development cycle are performed during the open-source licensing review? - ANSWER license compliance Which of the Ship (A5) deliverables of the security development cycle are performed during the final security review? - ANSWER Release and ship How can you establish your own SDL to build security into a process appropriate for your organization's needs based on agile? - ANSWER iterative development How can you establish your own SDL to build security into a process appropriate for your organization's needs based on devops? - ANSWER continuous integration and continuous deployments How can you establish your own SDL to build security into a process appropriate for your organization's needs based on cloud? - ANSWER API invocation processes dynamic analysis - ANSWER the analysis of computer software that is performed when executing programs on a real or virtual processor in real time fuzz testing - ANSWER automated or semi-automated testing that provides invalid, unexpected, or random data to the computer software program National Institute of Standards and Technology (NIST) - ANSWER provides research, information, and tools for government and corporate information security measurement model - ANSWER a set of data security methods that developers take to protect against vulnerabilities metric model - ANSWER allows an organization to determine the effectiveness of its security controls Open Web Application Security Project (OWASP) - ANSWER a flexible and prospective framework to build security into your software development organization static analysis - ANSWER the analysis of computer software that is performed without executing programs Agile methodology - ANSWER mixes traditional and new software development practices extreme programming (XP) - ANSWER a software development methodology that is intended to improve software quality and responsiveness Scrum - ANSWER flexible, holistic product development strategy where a development team works as a unit to reach a common goal V-model - ANSWER a variation of the waterfall model, where the stage is turned back upwards after the coding phase How can you establish your own SDL to build security into a process appropriate for your organization's needs based on digital enterprise? - ANSWER enables and improves business activities Which phase of penetration testing allows for remediation to be performed? - ANSWER Deploy Which key deliverable occurs during post-release support? - ANSWER third-party reviews Which business function of OpenSAMM is associated with governance? - ANSWER Policy and compliance Which business function of OpenSAMM is associated with construction? - ANSWER Threat assessment Which business function of OpenSAMM is associated with verification? - ANSWER Code review Which business function of OpenSAMM is associated with deployment? - ANSWER Vulnerability management What is the product risk profile? - ANSWER A security assessment deliverable that estimates the actual cost of the product. A software security team member has been tasked with creating a deliverable that provides details on where and to what degree sensitive customer information is collected, stored, or created within a new product offering. What does the team member need to deliver in order to meet the objective? - ANSWER Privacy impact assessment What is the first phase in the security development life cycle? - ANSWER A1 Security Assessment What are the three areas of compliance requirements? - ANSWER Legal, financial, and industry standards What term refers to how the system should function based on the environment in which the system will operate? - ANSWER operational requirements During what phase of SDL do all key stakeholders discuss, identify, and have common understandings of the security and privacy implications, considerations, and requirements? - ANSWER A1 Security Assessment What are the three areas of focus in secure software requirements? - ANSWER Gathering the software requirements, data classification, and managing data protection requirements

Content preview

WGU D487 SECURE SW DESIGN MOST RECENT
EXAM VERSION COMPLETE ACCURATE EXAM
QUESTIONS WITH DETAILED VERIFIED
ANSWERS (100% CORRECT ANSWERS)

Within OpenSAMM, what focuses on the processes and activities
related to organizational software development activities within
OpenSAMM practice areas? - ANSWER Governance
Which practice in the Ship (A5) phase of the security development cycle
verifies whether the product meets security mandates? - ANSWER A5
policy compliance analysis
Within OpenSAMM, what focuses on the processes and activities
related to creating software within development projects within
OpenSAMM practice areas? - ANSWER Construction


Which practice in the Ship (A5) phase of the security development
cycle uses tools to identify weaknesses in the product? - ANSWER
Vulnerability scan


Which post-release support activity should be completed when
companies are joining together? - ANSWER Security architectural
reviews


Which of the Ship (A5) deliverables of the security development cycle
are performed with A5 policy compliance analysis? - ANSWER analyze
activities and standards

, Which of the Ship (A5) deliverables of the security development cycle
are performed with code-assisted penetration testing? - ANSWER white-
box security testing


Which of the Ship (A5) deliverables of the security development cycle
are performed with open-source licensing review? - ANSWER license
compliance


Which of the Ship (A5) deliverables of the security development cycle
are performed with final security review? - ANSWER release and ship


Which phase of penetration testing allows for remediation to be
performed? - ANSWER deploy


Which key deliverable occurs during post-release support? - ANSWER
Third-party reviews


Which business function of OpenSAMM is associated with the
following core practices, governance? - ANSWER policy and
compliance


Which business function of OpenSAMM is associated with the
following core practices, construction? - ANSWER threat assessment


Which business function of OpenSAMM is associated with the
following core practices, verification? - ANSWER code review

, Which business function of OpenSAMM is associated with the
following core practices, deployment? - ANSWER vulnerability
management


What should the PIA include? - ANSWER summary of legislation,
required process steps, technologies and techniques, and additional
resources


What is the primary task of the PIA process? - ANSWER to determine
the need in the system, along with an initial definition of the problem to
be solved.


Which practice in the Ship (A5) phase of the security development
cycle verifies whether the product meets security mandates? - ANSWER
A5 policy compliance analysis


Which post-release support activity defines the process to communicate,
identify, and alleviate security threats? - ANSWER PRSA1: External
vulnerability disclosure response


Which post-release support activity defines the process to communicate,
identify, and alleviate security threats? - ANSWER PRSA1: External
vulnerability disclosure response


What are two core practice areas of the OWASP Security Assurance
Maturity Model (OpenSAMM)? - ANSWER Governance, Construction

Document information

Uploaded on
April 23, 2025
Number of pages
29
Written in
2024/2025
Type
Exam (elaborations)
Contains
Questions & answers
$12.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Sold
0
Followers
0
Items
49
Last sold
-


Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions