Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 73 pages
Exam (elaborations)

WGU D487 Secure Software Design Study Guide 2026/2027 | Complete Exam Prep & Verified Answers

Document preview thumbnail
Preview 4 out of 73 pages

WGU D487 Secure Software Design Study Guide 2026/2027 | Complete Exam Prep & Verified Answers

Content preview

D487 - Secure Software Design Knowlege Check
and Quiz, WGU D487 PRE-ASSESSMENT:
SECURE SOFTWARE DESIGN (KEO1) (PKEO)
Complete Exam Study Guide 2026 | 130+ Questions &
Answers with Detailed Explanations | Guaranteed
Pass Exam Prep
Description

This complete exam study guide contains 130+ carefully structured
questions and answers designed to help students master the most
important exam topics and achieve outstanding results. Each question is
accompanied by a clear and detailed explanation, making it easier to
understand key concepts and strengthen exam preparation.

The guide is organized in a simple and student-friendly format,
allowing learners to review essential material quickly while practicing
realistic exam-style questions. By working through these 130+ Q&A,
students can reinforce their knowledge, identify important topics, and
improve their confidence before taking the exam.

This resource is ideal for final exam revision, self-testing, and
comprehensive exam preparation, making it a valuable tool for
students who want a reliable study guide and a higher chance of
passing their exam successfully.




What are the two common best principles of software applications in the development
process? -answer ✅✅✅✅Quality Code & Secure Code

What ensures that the user has the appropriate role and privilege to view data? -answer
✅✅✅✅Authorization

,Which security goal is defined by "guarding against improper information modification or
destruction and ensuring information non-repudiation and authenticity"? -answer
✅✅✅✅Integrity

Which phase in an SDLC helps to define the problem and scope of any existing
systems and determine the objectives of new systems? -answer ✅✅✅✅Planning

What happens during a dynamic code review? -answer ✅✅✅✅Programmers monitor
system memory, functional behavior, response times, and overall performance.

How should you store your application user credentials in your application database? -
answer ✅✅✅✅Store credentials using salted hashes

Which software methodology resembles an assembly-line approach? -answer
✅✅✅✅Waterfall model

Which software methodology approach provides faster time to market and higher
business value? -answer ✅✅✅✅Agile model

In Scrum methodology, who is responsible for making decisions on the requirements? -
answer ✅✅✅✅Product Owner

What is the product risk profile? -answer ✅✅✅✅A security assessment deliverable
that estimates the actual cost of the product

A software security team member has been tasked with creating a deliverable that
provides details on where and to what degree sensitive customer information is
collected, stored, or created within a new product offering.

What does the team member need to deliver in order to meet the objective? -answer
✅✅✅✅Privacy impact assessment

A software security team member has been tasked with creating a threat model for the
login process of a new product.What is the first step the team member should take? -
answer ✅✅✅✅Identify security objectives

What are three parts of the STRIDE methodology? -answer ✅✅✅✅Spoofing,
Elevation, Tampering

What is the reason software security teams host discovery meetings with stakeholders
early in the development life cycle? -answer ✅✅✅✅To ensure that security is built into
the product from the start

,Why should a security team provide documented certification requirements during the
software assessment phase? -answer ✅✅✅✅Depending on the environment in which
the product resides, certifications may be required by corporate or government entities
before the software can be released to customers.

What are two items that should be included in the privacy impact assessment plan
regardless of which methodology is used? -answer ✅✅✅✅Required process steps &
Technologies and techniques

What are the goals of each SDL deliverable? - Product Risk Profile -answer
✅✅✅✅Estimate the actual cost of the product

What are the goals of each SDL deliverable? -SDL project outline -answer ✅✅✅✅Map
security activities to the development schedule

What are the goals of each SDL deliverable? - Threat profile -answer ✅✅✅✅Guide
security activities to protect the product from vulnerabilities

What are the goals of each SDL deliverable? -List of third-party software -answer
✅✅✅✅Identify the dependence on unmanaged software

What is a threat action that is designed to illegally access and use another person's
credentials? -answer ✅✅✅✅Spoofing

What are two steps of the threat modeling process? -answer ✅✅✅✅Survey The
application & Decompose the application

What do the "A" and the first "D" in the DREAD acronym represent? -answer
✅✅✅✅Damage & Affected Users

Which shape indicates each type of flow diagram element? - External elements -answer
✅✅✅✅Rectangle

Which shape indicates each type of flow diagram element? - Data Store -answer
✅✅✅✅Two Parallel horizontal lines

Which shape indicates each type of flow diagram element? - Data Flow -answer
✅✅✅✅Solid Line with an arrow

Which shape indicates each type of flow diagram element? - Trust Boundry -answer
✅✅✅✅Dashed Line

What are the two deliverables of the Architecture phase of the SDL? -answer
✅✅✅✅Threat Modeling artifacts & Policy compliance analysis

, What SDL security assessment deliverable is used as an input to an SDL architecture
process? -answer ✅✅✅✅Threat profile

Which software security testing technique tests the software from an external
perspective? -answer ✅✅✅✅Black box

Which security design principle states that an entity should be given the minimum
privileges and resources for a minimum period of time for a task? -answer
✅✅✅✅Least privilege

After the developer is done coding a functionality, when should code review be
completed? -answer ✅✅✅✅Within hours or the same day

What is the order that code reviews should follow in order to be effective? - Step 1 -
answer ✅✅✅✅Identify security code review objectives

What is the order that code reviews should follow in order to be effective? - Step 2 -
answer ✅✅✅✅Preform preliminary scan

What is the order that code reviews should follow in order to be effective? - Step 3 -
answer ✅✅✅✅Review code for security issues

What is the order that code reviews should follow in order to be effective? - Step 4 -
answer ✅✅✅✅Review for security issues unique to the architecture

When a software application handles personally identifiable information (PII) data, what
will be the Privacy Impact Rating? -answer ✅✅✅✅P1: High privacy risk

Which key success factor identifies threats to the software? -answer ✅✅✅✅Effective
threat modeling

What is the goal of design security review deliverables? -answer ✅✅✅✅To make
modifications to the design of software components based on security assessments

Which application scanner component is useful in identifying vulnerabilities such as
cookie misconfigurations and insecure configuration of HTTP response headers? -
answer ✅✅✅✅Passive scanner

Which type of attack occurs when an attacker uses malicious code in the data sent in a
form? -answer ✅✅✅✅Cross-site scripting

Which tools provide the given functions? - Self Managed Automatic Code Review
Product -answer ✅✅✅✅SonarQube

Document information

Uploaded on
March 13, 2026
Number of pages
73
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers
$11.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
TrustedExaminer
4.0
(9)
Sold
86
Followers
4
Items
3724
Last sold
4 days ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions