https://www.stuvia.com/user/Smartscroll
WGU-C706 Secure Software Design (Pre-
Assessment)Exam With Comprehensive Questions And
Correct Answers A+ Graded.
Which due diligence activity for supply chain security should occur in the initiation phase of the software
b b b b b b b b b b b b b b b b
acquisition life cycle? - CORRECT ANSWER✔✔Developing a request for proposal (RFP) that includes
b b b b b b b b b b b b b
supply chain security risk management
b b b b b
Which due diligence activity for supply chain security investigates the means by which data sets are shared
b b b b b b b b b b b b b b b b
and assessed? - CORRECT ANSWER✔✔A document exchange and review
b b b b b b b b b
Identification of the entity making the access request
b b b b b b b
Verification that the request has not changed since its initiation
b b b b b b b b b
Application of the appropriate authorization procedures
b b b b b
Reexamination of previously authorized requests by the same entity
b b b b b b b b
Which security design analysis is being described? - CORRECT ANSWER✔✔Complete mediation
b b b b b b b b b b
Which software security principle guards against the improper modification or destruction of information
b b b b b b b b b b b b
and ensures the nonrepudiation and authenticity of information? - CORRECT ANSWER✔✔Integrity
b b b b b b b b b b b
What type of functional security requirement involves receiving, processing, storing, transmitting, and
b b b b b b b b b b b
delivering in report form? - CORRECT ANSWER✔✔Primary dataflow
b b b b b b b b
, https://www.stuvia.com/user/Smartscroll
Which nonfunctional security requirement provides a way to capture information correctly and a way to
b b b b b b b b b b b b b b
store that information to help support later audits? - CORRECT ANSWER✔✔Logging
b b b b b b b b b b b
Which security concept refers to the quality of information that could cause harm or damage if disclosed? -
b b b b b b b b b b b b b b b b b
CORRECT ANSWER✔✔Sensitivity
b b
Which technology would be an example of an injection flaw, according to the OWASP Top 10? - CORRECT
b b b b b b b b b b b b b b b b b
ANSWER✔✔SQL
b
A company is creating a new software to track customer balance and wants to design a secure application.
b b b b b b b b b b b b b b b b b b
Which best practice should be applied? - CORRECT ANSWER✔✔Create multiple layers of protection so
b b b b b b b b b b b b b
that a subsequent layer provides protection if a layer is breached
b b b b b b b b b b b
A company is developing a secure software that has to be evaluated and tested by a large number of
b b b b b b b b b b b b b b b b b b
experts.
b b
Which security principle should be applied? - CORRECT ANSWER✔✔Open design
b b b b b b b b b
Which type of TCP scanning indicates that a system is moving to the second phase in a three-way TCP
b b b b b b b b b b b b b b b b b b
handshake? - CORRECT ANSWER✔✔TCP SYN scanning
b b b b b b
Which evaluation technique provides invalid, unexpected, or random data to the inputs of a computer
b b b b b b b b b b b b b b
software program? - CORRECT ANSWER✔✔Fuzz testing
b b b b b b
Which approach provides an opportunity to improve the software development life cycle by tailoring the
b b b b b b b b b b b b b b
process to the specific risks facing the organization? - CORRECT ANSWER✔✔Software assurance maturity
b b b b b b b b b b b b b
model (SAMM)
b b
WGU-C706 Secure Software Design (Pre-
Assessment)Exam With Comprehensive Questions And
Correct Answers A+ Graded.
Which due diligence activity for supply chain security should occur in the initiation phase of the software
b b b b b b b b b b b b b b b b
acquisition life cycle? - CORRECT ANSWER✔✔Developing a request for proposal (RFP) that includes
b b b b b b b b b b b b b
supply chain security risk management
b b b b b
Which due diligence activity for supply chain security investigates the means by which data sets are shared
b b b b b b b b b b b b b b b b
and assessed? - CORRECT ANSWER✔✔A document exchange and review
b b b b b b b b b
Identification of the entity making the access request
b b b b b b b
Verification that the request has not changed since its initiation
b b b b b b b b b
Application of the appropriate authorization procedures
b b b b b
Reexamination of previously authorized requests by the same entity
b b b b b b b b
Which security design analysis is being described? - CORRECT ANSWER✔✔Complete mediation
b b b b b b b b b b
Which software security principle guards against the improper modification or destruction of information
b b b b b b b b b b b b
and ensures the nonrepudiation and authenticity of information? - CORRECT ANSWER✔✔Integrity
b b b b b b b b b b b
What type of functional security requirement involves receiving, processing, storing, transmitting, and
b b b b b b b b b b b
delivering in report form? - CORRECT ANSWER✔✔Primary dataflow
b b b b b b b b
, https://www.stuvia.com/user/Smartscroll
Which nonfunctional security requirement provides a way to capture information correctly and a way to
b b b b b b b b b b b b b b
store that information to help support later audits? - CORRECT ANSWER✔✔Logging
b b b b b b b b b b b
Which security concept refers to the quality of information that could cause harm or damage if disclosed? -
b b b b b b b b b b b b b b b b b
CORRECT ANSWER✔✔Sensitivity
b b
Which technology would be an example of an injection flaw, according to the OWASP Top 10? - CORRECT
b b b b b b b b b b b b b b b b b
ANSWER✔✔SQL
b
A company is creating a new software to track customer balance and wants to design a secure application.
b b b b b b b b b b b b b b b b b b
Which best practice should be applied? - CORRECT ANSWER✔✔Create multiple layers of protection so
b b b b b b b b b b b b b
that a subsequent layer provides protection if a layer is breached
b b b b b b b b b b b
A company is developing a secure software that has to be evaluated and tested by a large number of
b b b b b b b b b b b b b b b b b b
experts.
b b
Which security principle should be applied? - CORRECT ANSWER✔✔Open design
b b b b b b b b b
Which type of TCP scanning indicates that a system is moving to the second phase in a three-way TCP
b b b b b b b b b b b b b b b b b b
handshake? - CORRECT ANSWER✔✔TCP SYN scanning
b b b b b b
Which evaluation technique provides invalid, unexpected, or random data to the inputs of a computer
b b b b b b b b b b b b b b
software program? - CORRECT ANSWER✔✔Fuzz testing
b b b b b b
Which approach provides an opportunity to improve the software development life cycle by tailoring the
b b b b b b b b b b b b b b
process to the specific risks facing the organization? - CORRECT ANSWER✔✔Software assurance maturity
b b b b b b b b b b b b b
model (SAMM)
b b