WGU C706 SECURE SOFTWARE DESIGN
FINAL TEST 2026 QUESTIONS WITH
CORRECT ANSWERS GRADED A+
◍ Which type of attack would a hacker use to exploit a vulnerability that
allows access to be increased to the administrator level?A RootkitB
WhalingC WaterholeD Dictionary.
Answer: A
◍ A video company has installed new software. The developers need to
establish a defense against zero-day attacks. What is the best way to manage
this vulnerability?.
Answer: Install the latest patches
◍ A company is developing a secure software that has to be evaluated and
tested by a large number of experts. Which security principle should be
applied?.
Answer: Open design
◍ What is an appropriate countermeasure to an escalation of privilege attack?.
Answer: Restricting access to specific operations through role-based access
controls
◍ Identification of the entity making the access requestVerification that the
request has not changed since its initiationApplication of the appropriate
authorization proceduresReexamination of previously authorized requests
by the same entityWhich security design analysis is being described?.
Answer: Complete mediation
◍ Which element is commonly addressed in a service-level agreement (SLA)?.
Answer: Service availability
,◍ A system developer is implementing a new sales system. The system
developer is concerned that unauthorized individuals may be able to view
sensitive customer financial data.Which family of nonfunctional
requirements should be considered as part of the acceptance criteria?A
IntegrityB AvailabilityC NonrepuditionD Confidentiality.
Answer: D
◍ Which configuration management security countermeasure implements least
privilege access control?.
Answer: Restricting file access to users based on authorization
◍ Which approach provides an opportunity to improve the software
development life cycle by tailoring the process to the specific risks facing
the organization?.
Answer: Software assurance maturity model (SAMM)
◍ Waterfall Methodology.
Answer: A project management approach that emphasizes a linear
progression from beginning to end of a project. This methodology, often
used by engineers, is front-loaded to rely on careful planning, detailed
documentation, and consecutive execution.Consists of seven stages:1.
Analysis2. Requirements3. Design4. Development5. Testing and
Integration6. Deployment7. Maintenance
◍ What is one advantage of dynamic code analysis?A Automated tools
produce false positives and false negativesB Automated tools provide a false
sense of security that everything is being addressedC Automated tools
provide flexibility on what to scan forD Automated tools are only as good as
the rules they are using to scan with.
Answer: C
◍ Which type of TCP scanning indicates that a system is moving to the second
phase in a three-way TCP handshake?A TCP SYN scanningB TCP ACK
scanningC TCP XMAS scanningD TCP Connect scanning.
Answer: A
, ◍ What is an agent in a distributed computing environment?A protocol that
encodes messages in a Web service setupB identifier used to uniquely
identify users, resources, and components within an environmentC program
that performs services in one environment on behalf of a principal in another
environmentD the middleware that establishes the relationship between
objects in a client/server environment.
Answer: C
◍ A company is developing a secure software that has to be evaluated and
tested by a large number of experts. Which security principle should be
applied?.
Answer: Open design
◍ Which due diligence activity for supply chain security investigates the
means by which data sets are shared and assessed?A on-site assessmentB
process policy reviewC third-party assessmentD document exchange and
review.
Answer: D
◍ What is a countermeasure against various forms of XML and XML path
injection attacks?.
Answer: XML attribute escaping
◍ Your company decides that a new software product must be purchased to
help the marketing staff manage their marketing campaigns and the
resources used. During which phase of the software acquisition process do
you document the software requirements?A Monitoring phaseB Maintaining
phaseC Planning phaseD Contracting phase.
Answer: C
◍ A company is developing a new software application that requires users to
log in using a username and password. The company needs to implement a
security control that is effective at preventing spoofing during the log-in
process.Which security control is effective at preventing this threat action?.
Answer: Authentication
FINAL TEST 2026 QUESTIONS WITH
CORRECT ANSWERS GRADED A+
◍ Which type of attack would a hacker use to exploit a vulnerability that
allows access to be increased to the administrator level?A RootkitB
WhalingC WaterholeD Dictionary.
Answer: A
◍ A video company has installed new software. The developers need to
establish a defense against zero-day attacks. What is the best way to manage
this vulnerability?.
Answer: Install the latest patches
◍ A company is developing a secure software that has to be evaluated and
tested by a large number of experts. Which security principle should be
applied?.
Answer: Open design
◍ What is an appropriate countermeasure to an escalation of privilege attack?.
Answer: Restricting access to specific operations through role-based access
controls
◍ Identification of the entity making the access requestVerification that the
request has not changed since its initiationApplication of the appropriate
authorization proceduresReexamination of previously authorized requests
by the same entityWhich security design analysis is being described?.
Answer: Complete mediation
◍ Which element is commonly addressed in a service-level agreement (SLA)?.
Answer: Service availability
,◍ A system developer is implementing a new sales system. The system
developer is concerned that unauthorized individuals may be able to view
sensitive customer financial data.Which family of nonfunctional
requirements should be considered as part of the acceptance criteria?A
IntegrityB AvailabilityC NonrepuditionD Confidentiality.
Answer: D
◍ Which configuration management security countermeasure implements least
privilege access control?.
Answer: Restricting file access to users based on authorization
◍ Which approach provides an opportunity to improve the software
development life cycle by tailoring the process to the specific risks facing
the organization?.
Answer: Software assurance maturity model (SAMM)
◍ Waterfall Methodology.
Answer: A project management approach that emphasizes a linear
progression from beginning to end of a project. This methodology, often
used by engineers, is front-loaded to rely on careful planning, detailed
documentation, and consecutive execution.Consists of seven stages:1.
Analysis2. Requirements3. Design4. Development5. Testing and
Integration6. Deployment7. Maintenance
◍ What is one advantage of dynamic code analysis?A Automated tools
produce false positives and false negativesB Automated tools provide a false
sense of security that everything is being addressedC Automated tools
provide flexibility on what to scan forD Automated tools are only as good as
the rules they are using to scan with.
Answer: C
◍ Which type of TCP scanning indicates that a system is moving to the second
phase in a three-way TCP handshake?A TCP SYN scanningB TCP ACK
scanningC TCP XMAS scanningD TCP Connect scanning.
Answer: A
, ◍ What is an agent in a distributed computing environment?A protocol that
encodes messages in a Web service setupB identifier used to uniquely
identify users, resources, and components within an environmentC program
that performs services in one environment on behalf of a principal in another
environmentD the middleware that establishes the relationship between
objects in a client/server environment.
Answer: C
◍ A company is developing a secure software that has to be evaluated and
tested by a large number of experts. Which security principle should be
applied?.
Answer: Open design
◍ Which due diligence activity for supply chain security investigates the
means by which data sets are shared and assessed?A on-site assessmentB
process policy reviewC third-party assessmentD document exchange and
review.
Answer: D
◍ What is a countermeasure against various forms of XML and XML path
injection attacks?.
Answer: XML attribute escaping
◍ Your company decides that a new software product must be purchased to
help the marketing staff manage their marketing campaigns and the
resources used. During which phase of the software acquisition process do
you document the software requirements?A Monitoring phaseB Maintaining
phaseC Planning phaseD Contracting phase.
Answer: C
◍ A company is developing a new software application that requires users to
log in using a username and password. The company needs to implement a
security control that is effective at preventing spoofing during the log-in
process.Which security control is effective at preventing this threat action?.
Answer: Authentication