100% satisfaction guarantee Immediately available after payment Both online and in PDF No strings attached 4.2 TrustPilot
logo-home
Exam (elaborations)

D385 Software Security and Testing – 100 Exam Q&A | Python, XSS, API Security, CORS | 2025/2026 | WGU

Rating
-
Sold
-
Pages
26
Grade
A+
Uploaded on
08-11-2025
Written in
2025/2026

This document features 100 updated and verified exam questions and answers for the D385 Software Security and Testing course offered by Western Governors University (WGU) for the 2025/2026 academic year. Specifically tailored for WGU students, it serves as a comprehensive and practical guide for mastering secure coding, API security, authentication protocols, error handling, and Python-based vulnerability prevention techniques. The content emphasizes real-world software security threats and testing techniques with code-based examples and memorization tips. It is particularly useful for students studying cybersecurity, software development, and secure systems engineering. The questions reflect real exam formatting and highlight correct answers and edge-case scenarios that often appear in WGU assessments. Key topics include: OWASP vulnerabilities: Cross-Site Scripting (XSS), SQL Injection, Broken Access Control Python security coding: use of eval(), validate(), assert, type(), isinstance() Secure logging and input handling: preventing log injection, using assertions, type checking Common attacks and defense: Man-in-the-Middle, DoS, code injection, token mismanagement API and HTTP protocol handling: status codes (200–500), headers (Authentication, User-Agent, CORS) Secure communication practices: token caching (MSAL), rate limiting, proper error response handling Serialization, hashing, and encryption: 3_256, AES CTR mode, secure deserialization Testing techniques: regression testing, preconditions/postconditions, response validation Ideal for: WGU students enrolled in the D385 course Software development and cybersecurity majors Python developers learning to implement secure practices Professionals preparing for software testing or secure coding certifications Anyone working with REST APIs, logging, or access control mechanisms With complete code examples, common output interpretations, and detailed reasoning behind the correct choices, this guide is optimized for both learning and high exam performance. Keywords: software security, WGU D385, Python secure coding, XSS, SQL injection, API security, CORS, HTTP status codes, assertion, eval, sanitize input, authentication headers, log injection, hashing, AES encryption, deserialization, access control, regression testing, secure REST API, man-in-the-middle, error handling

Show more Read less










Whoops! We can’t load your doc right now. Try again or contact support.

Document information

Uploaded on
November 8, 2025
Number of pages
26
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers

Subjects

Content preview

D385 Software Security and Testing
2025/2026 Exam Questions and Correct
Answers | New Update



Sanitize outbound log messages - 🧠 ANSWER ✔✔What is the primary

defense against log injection attacks?


Access the user's data - 🧠 ANSWER ✔✔An attacker exploits a cross-site

scripting vulnerability. What is the attacker able to do?


eval() - 🧠 ANSWER ✔✔Which Python function is prone to a potential code

injection attack?


Check functional preconditions and postconditions - 🧠 ANSWER ✔✔What

are two common defensive coding techniques?


test - 🧠 ANSWER ✔✔Which package is meant for internal use by Python

for regression testing?

,type() - 🧠 ANSWER ✔✔Which Python function is used for input validation?


Broken access control - 🧠 ANSWER ✔✔A security analyst has noticed a

vulnerability in which an attacker took over multiple users' accounts. Which

vulnerability did the security analyst encounter?


Implement resource and field-level access control - 🧠 ANSWER ✔✔When

creating a new user, an administrator must submit the following fields to an

API endpoint:




Name

Email Address

Password

IsAdmin




What is the best way to ensure the API is protected against privilege

escalation?


Exploiting query parameters - 🧠 ANSWER ✔✔Which method is used for a

SQL injection attack?

, response.content - 🧠 ANSWER ✔✔Which response method, when sent a

request, returns information about the server's response and is delivered

back to the console?


Override same starting policy for specific resources - 🧠 ANSWER ✔✔What

does cross-origin resource sharing (CORS) allow users to do?


MSAL - 🧠 ANSWER ✔✔Which protocol caches a token after it has been

acquired?


200 - 🧠 ANSWER ✔✔OK - Your request was successful


201 - 🧠 ANSWER ✔✔CREATED - Your request was accepted, and the

resource was created


400 - 🧠 ANSWER ✔✔BAD REQUEST - Your request is either wrong or

missing information


401 - 🧠 ANSWER ✔✔UNAUTHORIZED - Your request requires additional

permissions


403 - 🧠 ANSWER ✔✔FORBIDDEN - website can be reached, but more

permissions needed before accessing further




COPYRIGHT©PROFFKERRYMARTIN 2025/2026. YEAR PUBLISHED 2025. COMPANY REGISTRATION NUMBER: 619652435. TERMS OF USE.
PRIVACY STATEMENT. ALL RIGHTS RESERVED

Get to know the seller

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
PROFFKERRYMARTIN Liberty University
View profile
Follow You need to be logged in order to follow users or courses
Sold
117
Member since
10 months
Number of followers
2
Documents
8014
Last sold
2 hours ago
KERRYMARTIN

KERRYMARTIN EXAM HUB Assignments, Case Studies, Research, Essay writing service, Questions and Answers, Discussions etc. for students who want to see results twice as fast. I have done papers of various topics and complexities. I am punctual and always submit work on-deadline. I write engaging and informative content on all subjects. Send me your research papers, case studies, psychology papers, etc, and I’ll do them to the best of my abilities. Writing is my passion when it comes to academic work. I’ve got a good sense of structure and enjoy finding interesting ways to deliver information in any given paper. I love impressing clients with my work, and I am very punctual about deadlines. Send me your assignment and I’ll take it to the next level. I strive for my content to be of the highest quality. Your wishes come first— send me your requirements and I’ll make a piece of work with fresh ideas, consistent structure, and following the academic formatting rules. For every student you refer to me with an order that is completed and paid transparently, I will do one assignment for you, free of charge!!!!!!!!!!!!

Read more Read less
3.3

23 reviews

5
9
4
2
3
5
2
1
1
6

Recently viewed by you

Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Frequently asked questions