D487 - SECURE SOFTWARE DESIGN ACTUAL EXAM QUESTIONS AND ANSWERS (VERIFIED AND
WELL ELABORATED ANSWERS) LATEST UPDATE 2025/2026
Software Development Life Cycle (SDLC)
A structured process that enables the production of software
What are the 8 phases of the Software Development Lifecycle (SDLC)?
planning
requirements
design
implementation
testing
deployment
maintenance
end of life
SDLC Phase 1
planning - a vision and next steps are created
SDLC Phase 2
requirements - necessary software requirements are determined
SDLC Phase 3
design - requirements are prepared for the technical design
SDLC Phase 4
implementation - the resources involved in the application from a known resource are
determined
SDLC Phase 5
testing - software is tested to verify its functions through a known environment
SDLC Phase 6
deployment - security is pushed out
SDLC Phase 7
,maintenance - ongoing security monitoring is implemented
SDLC Phase 8
end of life - the proper steps for removing software completely are considered
Security Development Life Cycle (SDL)
A process that standardizes security best practices
Secure Code
A principle design in coding that refers to code security best practices, safeguards, and
protection against vulnerabilities
Threat Modeling
A structured process to protect against vulnerabilities
process to pinpoint security threats and potential vulnerabilities that will help prioritize
remediation
Application Security
developing, adding, and testing security features to prevent vulnerabilities within applications
Building Security in Maturing Model (BSIMM)
a study of real-world software security that allows you to develop your software security over
time
OWASP Software Assurance Maturity Model (SAMM)
flexible framework for building security into a software development organization
Open Web Application Security Project (OWASP)
A flexible and prospective framework to build security into your software development
organization for web applications
Static Analysis
the analysis of computer software that is performed without executing programs
Dynamic Analysis
the analysis of computer software that is performed when executing programs on a real or
virtual processor in real time
, Fuzz Testing
automated or semi-automated testing that provides invalid, unexpected, or random data to
the computer software program
National Institute of Standards and Technology (NIST)
provides research, information, and tools for government and corporate information security
Measurement Model
A set of data security methods that developers take to protect against vulnerabilities
Metric Model
Allows an organization to determine the effectiveness of its security controls
Waterfall Development
software development methodology that breaks down development activities into linear
sequential phases; each phase depends on the deliverables of the previous one and
corresponds to a specialization of tasks
Waterfall Phases (typical)
plan -> build -> test -> review -> deploy
Iterative Waterfall Development
each phase of a project is broken down into its own waterfall phases
Agile Development
software development methodology that delivers functionality in rapid iterations
called timeboxes, requiring limited planning but frequent communication. Mizes traditional and
new software development practices.
Scrum
framework for Agile that prescribes for teams to break work into goals to be completed
within sprints
flexible, holistic product development strategy where a development team works as a unit to
reach a common goal
Scrum Master (Scrum Role)
WELL ELABORATED ANSWERS) LATEST UPDATE 2025/2026
Software Development Life Cycle (SDLC)
A structured process that enables the production of software
What are the 8 phases of the Software Development Lifecycle (SDLC)?
planning
requirements
design
implementation
testing
deployment
maintenance
end of life
SDLC Phase 1
planning - a vision and next steps are created
SDLC Phase 2
requirements - necessary software requirements are determined
SDLC Phase 3
design - requirements are prepared for the technical design
SDLC Phase 4
implementation - the resources involved in the application from a known resource are
determined
SDLC Phase 5
testing - software is tested to verify its functions through a known environment
SDLC Phase 6
deployment - security is pushed out
SDLC Phase 7
,maintenance - ongoing security monitoring is implemented
SDLC Phase 8
end of life - the proper steps for removing software completely are considered
Security Development Life Cycle (SDL)
A process that standardizes security best practices
Secure Code
A principle design in coding that refers to code security best practices, safeguards, and
protection against vulnerabilities
Threat Modeling
A structured process to protect against vulnerabilities
process to pinpoint security threats and potential vulnerabilities that will help prioritize
remediation
Application Security
developing, adding, and testing security features to prevent vulnerabilities within applications
Building Security in Maturing Model (BSIMM)
a study of real-world software security that allows you to develop your software security over
time
OWASP Software Assurance Maturity Model (SAMM)
flexible framework for building security into a software development organization
Open Web Application Security Project (OWASP)
A flexible and prospective framework to build security into your software development
organization for web applications
Static Analysis
the analysis of computer software that is performed without executing programs
Dynamic Analysis
the analysis of computer software that is performed when executing programs on a real or
virtual processor in real time
, Fuzz Testing
automated or semi-automated testing that provides invalid, unexpected, or random data to
the computer software program
National Institute of Standards and Technology (NIST)
provides research, information, and tools for government and corporate information security
Measurement Model
A set of data security methods that developers take to protect against vulnerabilities
Metric Model
Allows an organization to determine the effectiveness of its security controls
Waterfall Development
software development methodology that breaks down development activities into linear
sequential phases; each phase depends on the deliverables of the previous one and
corresponds to a specialization of tasks
Waterfall Phases (typical)
plan -> build -> test -> review -> deploy
Iterative Waterfall Development
each phase of a project is broken down into its own waterfall phases
Agile Development
software development methodology that delivers functionality in rapid iterations
called timeboxes, requiring limited planning but frequent communication. Mizes traditional and
new software development practices.
Scrum
framework for Agile that prescribes for teams to break work into goals to be completed
within sprints
flexible, holistic product development strategy where a development team works as a unit to
reach a common goal
Scrum Master (Scrum Role)