Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Exam (elaborations)

D487 STUDY GUIDE EXAM (updated 2025) Questions & Answers | Latest Already Graded A+ UPDATE 2025|2026 D487 STUDY GUIDE EXAM (updated 2025) Questions & Answers | Latest Already Graded A+ UPDATE 2025|2026

Rating
-
Sold
-
Pages
7
Grade
A+
Uploaded on
09-10-2025
Written in
2025/2026

D487 STUDY GUIDE EXAM (updated 2025) Questions & Answers | Latest Already Graded A+ UPDATE 2025|2026

Institution
D487 STUDY
Course
D487 STUDY

Content preview

D487 STUDY

1. Building Security A study of real-world software security initiatives organized so that you can
In Maturity Model determine where you stand with your software security initiative and how to
(BSIMM) evolve your efforts over time

2. SAMM offers a roadmap and a well-defined maturity model for secure software
development and deployment, along with useful tools for self-assessment
and planning.

3. Core OpenSAMM ac- Governance
tivities Construction
Verification
Deployment

4. static analysis Source code of an application is reviewed manually or with automatic tools
without running the code

5. dynamic analysis Analysis and testing of a program occurs while it is being executed or run

6. Fuzzing Injection of randomized data into a software program in an attempt to find
system failures, memory leaks, error handling issues, and improper input
validation

7. OWASP ZAP -Open-source web application security scanner
-Can be used as a proxy to manipulate traffic running through it (even https)

8. ISO/IEC 27001 Specifies requirements for establishing, implementing, operating, moni-
toring, reviewing, maintaining and improving a documented information
security management system

9. ISO/IEC 17799 ISO/EIC is a joint committee that develops and maintains standards in the IT
industry. is an international code of practice for information security manage-
ment. This section defines confidentiality, integrity and availability controls.

10. ISO/IEC 27034
1/7

, D487 STUDY

A standard that provides guidance to help organizations embed security with-
in their processes that help secure applications running in the environment,
including application lifecycle processes

11. Software security a developer with an interest in security who helps amplify the security mes-
champion sage at the team level

12. waterfall methodolo- a sequential, activity-based process in which each phase in the SDLC is
gy performed sequentially from planning through implementation and main-
tenance

13. Agile Development A software development methodology that delivers functionality in rapid
iterations, measured in weeks, requiring frequent communication, develop-
ment, testing, and delivery.

14. Scrum an agile project management framework that helps teams structure and
manage their work through a set of values, principles, and practices

15. Daily scrum daily time-boxed event of 15 minutes, or less, for the Development Team
to re-plan the next day of development work during a Sprint. Updates are
reflected in the Sprint Backlog.

16. Sprint review A meeting that occurs after each sprint to show the product or process to
stakeholders for approval and to receive feedback.

17. Sprint retrospective an opportunity for the Scrum Team to inspect itself and create a plan for
improvements to be enacted during the next Sprint.

18. Sprint planning A collaborative event in Scrum in which the Scrum team plans the work for
the current sprint.

19. Threat Modeling Identify security objectives
Steps Survey the application
Decompose it
2/7

Written for

Institution
D487 STUDY
Course
D487 STUDY

Document information

Uploaded on
October 9, 2025
Number of pages
7
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers
$15.49
Get access to the full document:

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Get to know the seller

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
CodedNurse Nightingale College
View profile
Follow You need to be logged in order to follow users or courses
Sold
3887
Member since
1 year
Number of followers
24
Documents
10026
Last sold
3 days ago
coded

"I specialize in key academic areas such as Psychology, Nursing, Human Resource Management, and Mathematics. Providing students with top-quality work is my priority, and I always uphold the highest scholarly standards. This commitment has earned me the distinction of being a Gold-Rated Tutor on Stuvia. You can trust my work to help you achieve excellent grades!"

3.6

81 reviews

5
30
4
15
3
19
2
4
1
13

Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions