Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 3 out of 16 pages
Exam (elaborations)

D487 SECURE SOFTWARE DESIGN EXAMINATION TEST 2026 VERIFIED QUESTIONS AND SOLUTIONS ALREADY PASSED

Document preview thumbnail
Preview 3 out of 16 pages

D487 SECURE SOFTWARE DESIGN EXAMINATION TEST 2026 VERIFIED QUESTIONS AND SOLUTIONS ALREADY PASSED

Content preview

D487 SECURE SOFTWARE DESIGN
EXAMINATION TEST 2026 VERIFIED QUESTIONS
AND SOLUTIONS ALREADY PASSED

◉ Threat Modeling (Stages). Answer: 1. Identify Assets: Determine
what needs to be protected.
2. Identify Threats: Identify potential threats to those assets.
3. Identify Vulnerabilities: Analyze weaknesses that could be
exploited by threats.
4. Assess Risks: Evaluate the likelihood and impact of identified
threats exploiting vulnerabilities.
5. Mitigate Risks: Implement countermeasures to reduce or
eliminate identified risks


◉ PASTA Stages. Answer: - Define Objectives: Establish goals and
scope of the analysis.
- Create an Application Diagram: Visualize the application and its
components.
- Identify Threat Profiles: Define potential attacker personas and
their motivations.
- Analyze Threats: Assess how attackers could exploit vulnerabilities
to achieve their objectives.

,- Prioritize Threats: Rank threats based on their severity and
likelihood.
- Mitigate Threats: Develop and implement countermeasures to
address identified threats.


◉ Core OpenSAMM activities. Answer: Governance
Construction
Verification
Deployment


◉ static analysis. Answer: Source code of an application is reviewed
manually or with automatic tools without running the code


◉ dynamic analysis. Answer: Analysis and testing of a program
occurs while it is being executed or run


◉ Fuzzing. Answer: Injection of randomized data into a software
program in an attempt to find system failures, memory leaks, error
handling issues, and improper input validation


◉ OWASP ZAP. Answer: -Open-source web application security
scanner-Can be used as a proxy to manipulate traffic running
through it (even https)

, ◉ ISO/IEC 27001. Answer: Specifies requirements for establishing,
implementing, operating, monitoring, reviewing, maintaining and
improving a documented information security management system


◉ ISO/IEC 17799. Answer: ISO/EIC is a joint committee that
develops and maintains standards in the IT industry. 17799 is an
international code of practice for information security management.
This section defines confidentiality, integrity and availability
controls.


◉ ISO/IEC 27034. Answer: A standard that provides guidance to
help organizations embed security within their processes that help
secure applications running in the environment, including
application lifecycle processes


◉ Software security champion. Answer: a developer with an interest
in security who helps amplify the security message at the team level


◉ waterfall methodology. Answer: a sequential, activity-based
process in which each phase in the SDLC is performed sequentially
from planning through implementation and maintenance


◉ Agile Development. Answer: A software development
methodology that delivers functionality in rapid iterations,
measured in weeks, requiring frequent communication,
development, testing, and delivery.

Document information

Uploaded on
November 6, 2025
Number of pages
16
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers
$12.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
FocusFile7
4.0
(26)
Sold
260
Followers
4
Items
69070
Last sold
2 days ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions