WGU D487 SECURE SOFTWARE DESIGN
CERTIFICATION ACTUAL ASSESSMENT
LATEST EVALUATION 2026 FULL
QUESTIONS AND PRECISE EXTENSIVE
ELABORATED SOLUTIONS ALREADY
PASSED GRADED A+
⩥ Architecture (A2) phase. Answer: the second phase of the security
development life cycle that examines security from perspective of
business risks
⩥ data flow diagrams. Answer: a visual representation of the threat flow
⩥ denial of service. Answer: denying access to valid users
⩥ elevation of privilege. Answer: privileged access to resources for
gaining unauthorized access to information
⩥ information disclosure. Answer: read a file that one was not granted
access too
,⩥ PASTA. Answer: the process for attack simulation and threat analysis
that gives a software security team a repeatable framework for
identifying threats
⩥ repudiation. Answer: performing illegal operations in a system that
lacks the ability to trace the prohibited operations
⩥ risk model. Answer: assess vulnerabilities during the software
development process
⩥ software security policy. Answer: defines what needs to be protected
and how it will be protected
⩥ spoofing. Answer: illegally accessing and using another user's
credentials
⩥ tampering. Answer: maliciously changing or modifying persistent data
⩥ third-party codes. Answer: reusable software developed externally
from the organization's platforms
⩥ threat source. Answer: the entity carrying out the attack
, ⩥ threat vector. Answer: the path an attacker can take to exploit a
vulnerability
⩥ Trike. Answer: a unified conceptual framework for security auditing
⩥ DREAD risk model consists of. Answer: damage potential,
reproducibility, exploitability, affected users, and discoverability
⩥ Web Application Security Frame (aka Application Security Frame).
Answer: uses categories to organize common security vulnerabilities
with a focus on web software applications
⩥ five steps of threat modeling. Answer: identify security objectives,
survey the application, decompose it, identify threats, and identify
vulnerabilities
⩥ What is the first step the team member should take. Answer: Identify
security objectives
⩥ What are three parts of the STRIDE methodology. Answer: Spoofing,
elevation, tampering
⩥ What is the reason software security teams host discovery meetings
with stakeholders early in the development life cycle. Answer: To ensure
that security is built into the product from the start
CERTIFICATION ACTUAL ASSESSMENT
LATEST EVALUATION 2026 FULL
QUESTIONS AND PRECISE EXTENSIVE
ELABORATED SOLUTIONS ALREADY
PASSED GRADED A+
⩥ Architecture (A2) phase. Answer: the second phase of the security
development life cycle that examines security from perspective of
business risks
⩥ data flow diagrams. Answer: a visual representation of the threat flow
⩥ denial of service. Answer: denying access to valid users
⩥ elevation of privilege. Answer: privileged access to resources for
gaining unauthorized access to information
⩥ information disclosure. Answer: read a file that one was not granted
access too
,⩥ PASTA. Answer: the process for attack simulation and threat analysis
that gives a software security team a repeatable framework for
identifying threats
⩥ repudiation. Answer: performing illegal operations in a system that
lacks the ability to trace the prohibited operations
⩥ risk model. Answer: assess vulnerabilities during the software
development process
⩥ software security policy. Answer: defines what needs to be protected
and how it will be protected
⩥ spoofing. Answer: illegally accessing and using another user's
credentials
⩥ tampering. Answer: maliciously changing or modifying persistent data
⩥ third-party codes. Answer: reusable software developed externally
from the organization's platforms
⩥ threat source. Answer: the entity carrying out the attack
, ⩥ threat vector. Answer: the path an attacker can take to exploit a
vulnerability
⩥ Trike. Answer: a unified conceptual framework for security auditing
⩥ DREAD risk model consists of. Answer: damage potential,
reproducibility, exploitability, affected users, and discoverability
⩥ Web Application Security Frame (aka Application Security Frame).
Answer: uses categories to organize common security vulnerabilities
with a focus on web software applications
⩥ five steps of threat modeling. Answer: identify security objectives,
survey the application, decompose it, identify threats, and identify
vulnerabilities
⩥ What is the first step the team member should take. Answer: Identify
security objectives
⩥ What are three parts of the STRIDE methodology. Answer: Spoofing,
elevation, tampering
⩥ What is the reason software security teams host discovery meetings
with stakeholders early in the development life cycle. Answer: To ensure
that security is built into the product from the start