WGU C706 SECURE SOFTWARE DESIGN
ACTUAL EXAM PAPER 2026 QUESTIONS
WITH ANSWERS GRADED A+
◍ Which path illustrates the flow of activities through the SDL?A Architect
Test Code DesignB Code Design Architect TestC Design
Architect Code TestD Architect Design Code Test.
Answer: D
◍ Least Common Mechanism Design Principle.
Answer: Declares that mechanisms used to access resources should not be
shared.
◍ An application development team is designing and building an application
that interfaces with a back-end database.Which activity should be included
when constructing a threat model for the application?.
Answer: Decompose the application to understand how it interacts with
external entities
◍ A project manager is given the task to come up with nonfunctional
acceptance criteria requirements for business owners as part of a project
delivery.Which nonfunctional requirement should be applied to the
acceptance criteria?.
Answer: Evaluate test execution results
◍ Which nonfunctional security requirement provides a way to capture
information correctly and a way to store that information to help support
later audits?.
Answer: Logging
◍ A security administrator wants to prevent web-based code that has full
access to a Windows operating system when executing on user systems.
, Which technique should remediate this vulnerability?.
Answer: Prohibiting downloads of ActiveX content
◍ What is a known SDL metric used to measure protection against
vulnerabilities?.
Answer: The number of security defects found through static analysis tools
◍ Which tool assists in application development design layout as a part of
application development life cycle?A AggregationB DelphiC SpiralD
CASE.
Answer: D
◍ Which item is a phase of the change management process?.
Answer: Communication planning
◍ Software Capability Maturity Model (SW-CMM):Level 3 - Defined.
Answer: Formal practices/processes that are well understood and proactive.
Software developers operate according to a set of formal, documented
software development processes.
◍ Which configuration management security countermeasure implements least
privilege access control?.
Answer: Restricting file access to users based on authorization
◍ The ASF threat list describes a risk that may occur when a software
developer forgets to set an expiration for a cookie. Which countermeasure
addresses this vulnerability?.
Answer: User and session management
◍ Which nonfunctional security requirement provides a way to capture
information correctly and a way to store that information to help support
later audits?.
Answer: Logging
◍ Which type of attack involves exploiting a social engineering vulnerability
over voice communications?.
Answer: Vishing
, ◍ Which type of TCP scanning indicates that a system is moving to the second
phase in a three-way TCP handshake?.
Answer: TCP SYN scanning
◍ What is included in a typical job description of a software security
champion (SSC)?.
Answer: Consider all possible paths of attack or exploits
◍ What is a step for constructing a threat model for a project when using
practical risk analysis?.
Answer: Make a list of what you are trying to protect
◍ __________ is the application of multiple layers of protection, such that a
subsequent layer will provide protection if a previous layer is breached.A
Least privilegeB Separation of dutiesC Defense in depthD Fail safe policy.
Answer: C
◍ A company is creating a new software to track customer balance and wants
to design a secure application. Which best practice should be applied?.
Answer: Create multiple layers of protection so that a subsequent layer
provides protection if a layer is breached
◍ Which technique should be used to detect a software vulnerability that
causes extra characters to appear in data fields of a front-facing web
application?.
Answer: Static analysis
◍ Which due diligence activity for supply chain security should occur in the
initiation phase of the software acquisition life cycle?.
Answer: Developing a request for proposal (RFP) that includes supply chain
security risk management
◍ A system administrator wants to use physical controls to prevent
unauthorized access to information that belongs to users at a different
security level.Which strategy would prevent this problem?.
Answer: Hardware segmentation
ACTUAL EXAM PAPER 2026 QUESTIONS
WITH ANSWERS GRADED A+
◍ Which path illustrates the flow of activities through the SDL?A Architect
Test Code DesignB Code Design Architect TestC Design
Architect Code TestD Architect Design Code Test.
Answer: D
◍ Least Common Mechanism Design Principle.
Answer: Declares that mechanisms used to access resources should not be
shared.
◍ An application development team is designing and building an application
that interfaces with a back-end database.Which activity should be included
when constructing a threat model for the application?.
Answer: Decompose the application to understand how it interacts with
external entities
◍ A project manager is given the task to come up with nonfunctional
acceptance criteria requirements for business owners as part of a project
delivery.Which nonfunctional requirement should be applied to the
acceptance criteria?.
Answer: Evaluate test execution results
◍ Which nonfunctional security requirement provides a way to capture
information correctly and a way to store that information to help support
later audits?.
Answer: Logging
◍ A security administrator wants to prevent web-based code that has full
access to a Windows operating system when executing on user systems.
, Which technique should remediate this vulnerability?.
Answer: Prohibiting downloads of ActiveX content
◍ What is a known SDL metric used to measure protection against
vulnerabilities?.
Answer: The number of security defects found through static analysis tools
◍ Which tool assists in application development design layout as a part of
application development life cycle?A AggregationB DelphiC SpiralD
CASE.
Answer: D
◍ Which item is a phase of the change management process?.
Answer: Communication planning
◍ Software Capability Maturity Model (SW-CMM):Level 3 - Defined.
Answer: Formal practices/processes that are well understood and proactive.
Software developers operate according to a set of formal, documented
software development processes.
◍ Which configuration management security countermeasure implements least
privilege access control?.
Answer: Restricting file access to users based on authorization
◍ The ASF threat list describes a risk that may occur when a software
developer forgets to set an expiration for a cookie. Which countermeasure
addresses this vulnerability?.
Answer: User and session management
◍ Which nonfunctional security requirement provides a way to capture
information correctly and a way to store that information to help support
later audits?.
Answer: Logging
◍ Which type of attack involves exploiting a social engineering vulnerability
over voice communications?.
Answer: Vishing
, ◍ Which type of TCP scanning indicates that a system is moving to the second
phase in a three-way TCP handshake?.
Answer: TCP SYN scanning
◍ What is included in a typical job description of a software security
champion (SSC)?.
Answer: Consider all possible paths of attack or exploits
◍ What is a step for constructing a threat model for a project when using
practical risk analysis?.
Answer: Make a list of what you are trying to protect
◍ __________ is the application of multiple layers of protection, such that a
subsequent layer will provide protection if a previous layer is breached.A
Least privilegeB Separation of dutiesC Defense in depthD Fail safe policy.
Answer: C
◍ A company is creating a new software to track customer balance and wants
to design a secure application. Which best practice should be applied?.
Answer: Create multiple layers of protection so that a subsequent layer
provides protection if a layer is breached
◍ Which technique should be used to detect a software vulnerability that
causes extra characters to appear in data fields of a front-facing web
application?.
Answer: Static analysis
◍ Which due diligence activity for supply chain security should occur in the
initiation phase of the software acquisition life cycle?.
Answer: Developing a request for proposal (RFP) that includes supply chain
security risk management
◍ A system administrator wants to use physical controls to prevent
unauthorized access to information that belongs to users at a different
security level.Which strategy would prevent this problem?.
Answer: Hardware segmentation