WGU D487 SECURE SW DESIGN OA
EXAM 2026 QUESTIONS AND
ANSWERS
Which practice in the Ship (A5) phase of the security development cycle verifies
whether the product meets security mandates? - Correct answer-A5 policy
compliance analysis
Which post-release support activity defines the process to communicate, identify,
and alleviate security threats? - Correct answer-PRSA1: External vulnerability
disclosure response
What are two core practice areas of the OWASP Security Assurance Maturity
Model (OpenSAMM)? - Correct answer-Governance, Construction
Which practice in the Ship (A5) phase of the security development cycle uses tools
to identify weaknesses in the product? - Correct answer-Vulnerability scan
Which post-release support activity should be completed when companies are
joining together? - Correct answer-Security architectural reviews
©COPYRIGHT 2025, ALL RIGHTS RESERVED 1
,Which of the Ship (A5) deliverables of the security development cycle are
performed during the A5 policy compliance analysis? - Correct answer-Analyze
activities and standards
Which of the Ship (A5) deliverables of the security development cycle are
performed during the code-assisted penetration testing? - Correct answer-white-
box security test
Which of the Ship (A5) deliverables of the security development cycle are
performed during the open-source licensing review? - Correct answer-license
compliance
Which of the Ship (A5) deliverables of the security development cycle are
performed during the final security review? - Correct answer-Release and ship
How can you establish your own SDL to build security into a process appropriate
for your organization's needs based on agile? - Correct answer-iterative
development
How can you establish your own SDL to build security into a process appropriate
for your organization's needs based on devops? - Correct answer-continuous
integration and continuous deployments
©COPYRIGHT 2025, ALL RIGHTS RESERVED 2
, How can you establish your own SDL to build security into a process appropriate
for your organization's needs based on cloud? - Correct answer-API invocation
processes
How can you establish your own SDL to build security into a process appropriate
for your organization's needs based on digital enterprise? - Correct answer-enables
and improves business activities
Which phase of penetration testing allows for remediation to be performed? -
Correct answer-Deploy
Which key deliverable occurs during post-release support? - Correct answer-third-
party reviews
Which business function of OpenSAMM is associated with governance? - Correct
answer-Policy and compliance
Which business function of OpenSAMM is associated with construction? - Correct
answer-Threat assessment
Which business function of OpenSAMM is associated with verification? - Correct
answer-Code review
Which business function of OpenSAMM is associated with deployment? - Correct
answer-Vulnerability management
©COPYRIGHT 2025, ALL RIGHTS RESERVED 3
EXAM 2026 QUESTIONS AND
ANSWERS
Which practice in the Ship (A5) phase of the security development cycle verifies
whether the product meets security mandates? - Correct answer-A5 policy
compliance analysis
Which post-release support activity defines the process to communicate, identify,
and alleviate security threats? - Correct answer-PRSA1: External vulnerability
disclosure response
What are two core practice areas of the OWASP Security Assurance Maturity
Model (OpenSAMM)? - Correct answer-Governance, Construction
Which practice in the Ship (A5) phase of the security development cycle uses tools
to identify weaknesses in the product? - Correct answer-Vulnerability scan
Which post-release support activity should be completed when companies are
joining together? - Correct answer-Security architectural reviews
©COPYRIGHT 2025, ALL RIGHTS RESERVED 1
,Which of the Ship (A5) deliverables of the security development cycle are
performed during the A5 policy compliance analysis? - Correct answer-Analyze
activities and standards
Which of the Ship (A5) deliverables of the security development cycle are
performed during the code-assisted penetration testing? - Correct answer-white-
box security test
Which of the Ship (A5) deliverables of the security development cycle are
performed during the open-source licensing review? - Correct answer-license
compliance
Which of the Ship (A5) deliverables of the security development cycle are
performed during the final security review? - Correct answer-Release and ship
How can you establish your own SDL to build security into a process appropriate
for your organization's needs based on agile? - Correct answer-iterative
development
How can you establish your own SDL to build security into a process appropriate
for your organization's needs based on devops? - Correct answer-continuous
integration and continuous deployments
©COPYRIGHT 2025, ALL RIGHTS RESERVED 2
, How can you establish your own SDL to build security into a process appropriate
for your organization's needs based on cloud? - Correct answer-API invocation
processes
How can you establish your own SDL to build security into a process appropriate
for your organization's needs based on digital enterprise? - Correct answer-enables
and improves business activities
Which phase of penetration testing allows for remediation to be performed? -
Correct answer-Deploy
Which key deliverable occurs during post-release support? - Correct answer-third-
party reviews
Which business function of OpenSAMM is associated with governance? - Correct
answer-Policy and compliance
Which business function of OpenSAMM is associated with construction? - Correct
answer-Threat assessment
Which business function of OpenSAMM is associated with verification? - Correct
answer-Code review
Which business function of OpenSAMM is associated with deployment? - Correct
answer-Vulnerability management
©COPYRIGHT 2025, ALL RIGHTS RESERVED 3