WGU C706 SECURE SOFTWARE DESIGN
PRACTICE EXAMINATION 2026
QUESTIONS WITH ANSWERS GRADED A+
◍ Which approach provides an opportunity to improve the software
development life cycle by tailoring the process to the specific risks facing
the organization?.
Answer: Software assurance maturity model (SAMM)
◍ V-Model (which is short for verification and validation).
Answer: Quite similar to the waterfall model. A testing phase is
incorporated into each development stage to catch potential bugs and
defects.It's incredibly disciplined and requires a rigorous timeline. But in
theory, it illuminates the shortcomings of the main waterfall model by
preventing larger bugs from spiraling out of control.
◍ Which role requires the technical capability to be trained as a software
security architect who then assists the centralized software security group
with architecture security analysis and threat modeling?.
Answer: Software champion
◍ What is a countermeasure against various forms of XML and XML path
injection attacks?.
Answer: XML attribute escaping
◍ Which element is commonly addressed in a service-level agreement (SLA)?.
Answer: Service availability
◍ What type of functional security requirement involves receiving, processing,
storing, transmitting, and delivering in report form?.
Answer: Primary dataflow
,◍ ___________ modeling and ____________ surface validation are perhaps
the most time-consuming, misunderstood, and difficult parts of the SDL.
This requires the attention of the most seasoned and experienced person of
the software security team: the software security architect..
Answer: Threat, attack
◍ A user was given a task to identify a nonfunctional acceptance criteria.
Which nonfunctional requirement should be applied to the acceptance
criteria?.
Answer: Review of the most recent test results
◍ What type of software threat occurs when password resets reveal password
hints and valid usernames, according to the Application Security Frame
(ASF)?.
Answer: Authentication
◍ Which type of cyberattacks are often intended to elevate awareness of a
topic?.
Answer: Sociopolitical attacks
◍ What is an appropriate countermeasure to an escalation of privilege attack?.
Answer: Restricting access to specific operations through role-based access
controls
◍ Which countermeasure is used to mitigate SQL injection attacks?.
Answer: Query parameterization
◍ A system developer is implementing a new sales system. The system
developer is concerned that unauthorized individuals may be able to view
sensitive customer financial data.Which family of nonfunctional
requirements should be considered as part of the acceptance criteria?.
Answer: Confidentiality
◍ Which technique can be used by an attacker to compromise password
security when a password such as "123456" is used by an organization?.
Answer: Brute-force attack
, ◍ What type of functional security requirement involves receiving, processing,
storing, transmitting, and delivering in report form?.
Answer: Primary dataflow
◍ Which type of virus installs itself under the anti-virus system and intercepts
any calls that the anti-virus system makes to the operating system?A script
virusB tunneling virusC boot sector virusD meme virus.
Answer: B
◍ Which attack aims to make web service unavailable or unusable?.
Answer: Denial-of-service
◍ A video company has installed new software. The developers need to
establish a defense against zero-day attacks. What is the best way to manage
this vulnerability?.
Answer: Install the latest patches
◍ _________ means that designs that are kept secret versus designs that are
open to scrutiny are evaluated by the community at large..
Answer: Open design
◍ Which countermeasure is used to mitigate SQL injection attacks?.
Answer: Query parameterization
◍ An undocumented command sequence is allowing unauthorized access to a
software system. What type of software defect allows this vulnerability?.
Answer: Backdoor
◍ A company is developing a new software application that requires users to
log in using a username and password. The company needs to implement a
security control that is effective at preventing spoofing during the log-in
process.Which security control is effective at preventing this threat action?.
Answer: Authentication
◍ Release Control.
Answer: Once changes from change control are finalized, they are approved
for release via the release control procedure. Includes ensuring
PRACTICE EXAMINATION 2026
QUESTIONS WITH ANSWERS GRADED A+
◍ Which approach provides an opportunity to improve the software
development life cycle by tailoring the process to the specific risks facing
the organization?.
Answer: Software assurance maturity model (SAMM)
◍ V-Model (which is short for verification and validation).
Answer: Quite similar to the waterfall model. A testing phase is
incorporated into each development stage to catch potential bugs and
defects.It's incredibly disciplined and requires a rigorous timeline. But in
theory, it illuminates the shortcomings of the main waterfall model by
preventing larger bugs from spiraling out of control.
◍ Which role requires the technical capability to be trained as a software
security architect who then assists the centralized software security group
with architecture security analysis and threat modeling?.
Answer: Software champion
◍ What is a countermeasure against various forms of XML and XML path
injection attacks?.
Answer: XML attribute escaping
◍ Which element is commonly addressed in a service-level agreement (SLA)?.
Answer: Service availability
◍ What type of functional security requirement involves receiving, processing,
storing, transmitting, and delivering in report form?.
Answer: Primary dataflow
,◍ ___________ modeling and ____________ surface validation are perhaps
the most time-consuming, misunderstood, and difficult parts of the SDL.
This requires the attention of the most seasoned and experienced person of
the software security team: the software security architect..
Answer: Threat, attack
◍ A user was given a task to identify a nonfunctional acceptance criteria.
Which nonfunctional requirement should be applied to the acceptance
criteria?.
Answer: Review of the most recent test results
◍ What type of software threat occurs when password resets reveal password
hints and valid usernames, according to the Application Security Frame
(ASF)?.
Answer: Authentication
◍ Which type of cyberattacks are often intended to elevate awareness of a
topic?.
Answer: Sociopolitical attacks
◍ What is an appropriate countermeasure to an escalation of privilege attack?.
Answer: Restricting access to specific operations through role-based access
controls
◍ Which countermeasure is used to mitigate SQL injection attacks?.
Answer: Query parameterization
◍ A system developer is implementing a new sales system. The system
developer is concerned that unauthorized individuals may be able to view
sensitive customer financial data.Which family of nonfunctional
requirements should be considered as part of the acceptance criteria?.
Answer: Confidentiality
◍ Which technique can be used by an attacker to compromise password
security when a password such as "123456" is used by an organization?.
Answer: Brute-force attack
, ◍ What type of functional security requirement involves receiving, processing,
storing, transmitting, and delivering in report form?.
Answer: Primary dataflow
◍ Which type of virus installs itself under the anti-virus system and intercepts
any calls that the anti-virus system makes to the operating system?A script
virusB tunneling virusC boot sector virusD meme virus.
Answer: B
◍ Which attack aims to make web service unavailable or unusable?.
Answer: Denial-of-service
◍ A video company has installed new software. The developers need to
establish a defense against zero-day attacks. What is the best way to manage
this vulnerability?.
Answer: Install the latest patches
◍ _________ means that designs that are kept secret versus designs that are
open to scrutiny are evaluated by the community at large..
Answer: Open design
◍ Which countermeasure is used to mitigate SQL injection attacks?.
Answer: Query parameterization
◍ An undocumented command sequence is allowing unauthorized access to a
software system. What type of software defect allows this vulnerability?.
Answer: Backdoor
◍ A company is developing a new software application that requires users to
log in using a username and password. The company needs to implement a
security control that is effective at preventing spoofing during the log-in
process.Which security control is effective at preventing this threat action?.
Answer: Authentication
◍ Release Control.
Answer: Once changes from change control are finalized, they are approved
for release via the release control procedure. Includes ensuring