Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 2 out of 14 pages
Exam (elaborations)

WGU D487 - SECURE SOFTWARE DESIGN EXAM WITH QUESTIONS AND CORRECT ANSWERS || LATEST UPDATE 2024/2025

Document preview thumbnail
Preview 2 out of 14 pages

WGU D487 - SECURE SOFTWARE DESIGN EXAM WITH QUESTIONS AND CORRECT ANSWERS || LATEST UPDATE 2024/2025

Content preview

WGU D487 - SECURE SOFTWARE DESIGN EXAM
WITH QUESTIONS AND CORRECT ANSWERS ||
LATEST UPDATE 2024/2025
Building Security In Maturity Model (BSIMM) - ...(ANSWERS)....A study of real-
world software security initiatives organized so that you can determine where
you stand with your software security initiative and how to evolve your efforts
over time



SAMM - ...(ANSWERS)....offers a roadmap and a well-defined maturity model for
secure software development and deployment, along with useful tools for self-
assessment and planning.



Core OpenSAMM activities - ...(ANSWERS)....Governance

Construction

Verification

Deployment



static analysis - ...(ANSWERS)....Source code of an application is reviewed
manually or with automatic tools without running the code



dynamic analysis - ...(ANSWERS)....Analysis and testing of a program occurs while
it is being executed or run

, Fuzzing - ...(ANSWERS)....Injection of randomized data into a software program in
an attempt to find system failures, memory leaks, error handling issues, and
improper input validation



OWASP ZAP - ...(ANSWERS)....-Open-source web application security scanner-Can
be used as a proxy to manipulate traffic running through it (even https)



ISO/IEC 27001 - ...(ANSWERS)....Specifies requirements for establishing,
implementing, operating, monitoring, reviewing, maintaining and improving a
documented information security management system



ISO/IEC 17799 - ...(ANSWERS)....ISO/EIC is a joint committee that develops and
maintains standards in the IT industry. 17799 is an international code of practice
for information security management. This section defines confidentiality,
integrity and availability controls.



ISO/IEC 27034 - ...(ANSWERS)....A standard that provides guidance to help
organizations embed security within their processes that help secure applications
running in the environment, including application lifecycle processes



Software security champion - ...(ANSWERS)....a developer with an interest in
security who helps amplify the security message at the team level



waterfall methodology - ...(ANSWERS)....a sequential, activity-based process in
which each phase in the SDLC is performed sequentially from planning through
implementation and maintenance

Document information

Uploaded on
July 20, 2025
Number of pages
14
Written in
2024/2025
Type
Exam (elaborations)
Contains
Questions & answers
Free
Download

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Sold
322
Followers
0
Items
1988
Last sold
2 days ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions