WGU D487 Secure Software Design Exam
20252/026 – Versions A & B
Secure Architecture (Questions 1–15)
Question 1
In which phase of the SDLC does the secure and complete removal of an application occur?
A. End of life phase
B. Design phase
C. Testing phase
D. Implementation phase
Correct Answer: A. End of life phase
Explanation: The end of life phase involves securely removing applications, including data
sanitization and system decommissioning, to prevent vulnerabilities. Design (B), testing (C), and
implementation (D) focus on development and deployment. Ransome et al., 2023, Ch. 8; web:0.
Question 2
What is the purpose of the Security Assessment (A1) phase in the SDL?
A. Execute security test cases
B. Identify product risks and create security milestones
C. Perform dynamic analysis
D. Write initial code
Correct Answer: B. Identify product risks and create security milestones
Explanation: The A1 phase identifies risks and outlines security milestones for the project.
Testing (A, C) occurs later, and coding (D) is in implementation. Studocu, D487 Course
Summary, 2025; web:14.
Question 3
Which deliverable ensures a product adheres to organizational security rules?
A. Threat modeling artifacts
B. Policy compliance analysis
C. Business requirements
D. Risk mitigation plan
,Correct Answer: B. Policy compliance analysis
Explanation: Policy compliance analysis verifies alignment with security policies. Artifacts (A)
document threats, requirements (C) define functionality, and plans (D) address risks. Ransome et
al., 2023, Ch. 4; web:2.
Question 4
What is the role of a software security architect in the SDL?
A. Writing feature logic
B. Designing secure coding practices
C. Facilitating scrum ceremonies
D. Conducting user acceptance testing
Correct Answer: B. Designing secure coding practices
Explanation: Security architects design and implement secure practices. Coding (A) is for
developers, facilitating (C) is for scrum masters, and testing (D) is for QA. Studocu, D487
Course Summary, 2025; web:18.
Question 5
Which SDL phase examines security from a business risk perspective?
A. Security Assessment (A1)
B. Architecture (A2)
C. Testing phase
D. Deployment phase
Correct Answer: B. Architecture (A2)
Explanation: The A2 phase evaluates security in the context of business risks, integrating threat
modeling. A1 (A) identifies risks, testing (C) verifies functionality, and deployment (D) releases
software. Studocu, D487 Course Summary, 2025; web:14.
Question 6
What is a key activity in the Architecture (A2) phase?
A. Penetration testing
B. Application decomposition
C. User training
D. Code deployment
Correct Answer: B. Application decomposition
Explanation: Application decomposition breaks down the system to identify vulnerabilities.
Testing (A), training (C), and deployment (D) occur in later phases. Ransome et al., 2023, Ch. 4;
web:12.
Question 7
, Which framework provides a roadmap for secure software development?
A. ISO 27001
B. OWASP SAMM
C. BSIMM
D. NIST 800-53
Correct Answer: B. OWASP SAMM
Explanation: OWASP SAMM offers a maturity model for secure software practices. BSIMM
(C) studies initiatives, ISO 27001 (A) is for security management, and NIST 800-53 (D) is for
controls. Ransome et al., 2023, Ch. 9; web:10.
Question 8
What does a policy compliance analysis include?
A. Metrics for project success
B. Data flow diagrams
C. Alignment with security standards
D. User interface designs
Correct Answer: C. Alignment with security standards
Explanation: Policy compliance ensures adherence to standards like GDPR or PCI-DSS.
Metrics (A), diagrams (B), and designs (D) are unrelated. Ransome et al., 2023, Ch. 4; web:2.
Question 9
What is the purpose of the SDL project outline?
A. Estimate product costs
B. Map security activities to the SDLC
C. Identify third-party software
D. Document user requirements
Correct Answer: B. Map security activities to the SDLC
Explanation: The SDL project outline aligns security tasks with SDLC phases. Costs (A),
software (C), and requirements (D) are separate deliverables. Ransome et al., 2023, Ch. 3;
web:12.
Question 10
Which role facilitates communication and removes roadblocks in a scrum team?
A. Product owner
B. Software developer
C. Scrum master
D. QA analyst
Correct Answer: C. Scrum master
Explanation: The scrum master facilitates ceremonies and resolves issues. Product owners (A)
20252/026 – Versions A & B
Secure Architecture (Questions 1–15)
Question 1
In which phase of the SDLC does the secure and complete removal of an application occur?
A. End of life phase
B. Design phase
C. Testing phase
D. Implementation phase
Correct Answer: A. End of life phase
Explanation: The end of life phase involves securely removing applications, including data
sanitization and system decommissioning, to prevent vulnerabilities. Design (B), testing (C), and
implementation (D) focus on development and deployment. Ransome et al., 2023, Ch. 8; web:0.
Question 2
What is the purpose of the Security Assessment (A1) phase in the SDL?
A. Execute security test cases
B. Identify product risks and create security milestones
C. Perform dynamic analysis
D. Write initial code
Correct Answer: B. Identify product risks and create security milestones
Explanation: The A1 phase identifies risks and outlines security milestones for the project.
Testing (A, C) occurs later, and coding (D) is in implementation. Studocu, D487 Course
Summary, 2025; web:14.
Question 3
Which deliverable ensures a product adheres to organizational security rules?
A. Threat modeling artifacts
B. Policy compliance analysis
C. Business requirements
D. Risk mitigation plan
,Correct Answer: B. Policy compliance analysis
Explanation: Policy compliance analysis verifies alignment with security policies. Artifacts (A)
document threats, requirements (C) define functionality, and plans (D) address risks. Ransome et
al., 2023, Ch. 4; web:2.
Question 4
What is the role of a software security architect in the SDL?
A. Writing feature logic
B. Designing secure coding practices
C. Facilitating scrum ceremonies
D. Conducting user acceptance testing
Correct Answer: B. Designing secure coding practices
Explanation: Security architects design and implement secure practices. Coding (A) is for
developers, facilitating (C) is for scrum masters, and testing (D) is for QA. Studocu, D487
Course Summary, 2025; web:18.
Question 5
Which SDL phase examines security from a business risk perspective?
A. Security Assessment (A1)
B. Architecture (A2)
C. Testing phase
D. Deployment phase
Correct Answer: B. Architecture (A2)
Explanation: The A2 phase evaluates security in the context of business risks, integrating threat
modeling. A1 (A) identifies risks, testing (C) verifies functionality, and deployment (D) releases
software. Studocu, D487 Course Summary, 2025; web:14.
Question 6
What is a key activity in the Architecture (A2) phase?
A. Penetration testing
B. Application decomposition
C. User training
D. Code deployment
Correct Answer: B. Application decomposition
Explanation: Application decomposition breaks down the system to identify vulnerabilities.
Testing (A), training (C), and deployment (D) occur in later phases. Ransome et al., 2023, Ch. 4;
web:12.
Question 7
, Which framework provides a roadmap for secure software development?
A. ISO 27001
B. OWASP SAMM
C. BSIMM
D. NIST 800-53
Correct Answer: B. OWASP SAMM
Explanation: OWASP SAMM offers a maturity model for secure software practices. BSIMM
(C) studies initiatives, ISO 27001 (A) is for security management, and NIST 800-53 (D) is for
controls. Ransome et al., 2023, Ch. 9; web:10.
Question 8
What does a policy compliance analysis include?
A. Metrics for project success
B. Data flow diagrams
C. Alignment with security standards
D. User interface designs
Correct Answer: C. Alignment with security standards
Explanation: Policy compliance ensures adherence to standards like GDPR or PCI-DSS.
Metrics (A), diagrams (B), and designs (D) are unrelated. Ransome et al., 2023, Ch. 4; web:2.
Question 9
What is the purpose of the SDL project outline?
A. Estimate product costs
B. Map security activities to the SDLC
C. Identify third-party software
D. Document user requirements
Correct Answer: B. Map security activities to the SDLC
Explanation: The SDL project outline aligns security tasks with SDLC phases. Costs (A),
software (C), and requirements (D) are separate deliverables. Ransome et al., 2023, Ch. 3;
web:12.
Question 10
Which role facilitates communication and removes roadblocks in a scrum team?
A. Product owner
B. Software developer
C. Scrum master
D. QA analyst
Correct Answer: C. Scrum master
Explanation: The scrum master facilitates ceremonies and resolves issues. Product owners (A)