WGU D487 PRACTICE EXAMINATION 2026
QUESTIONS WITH ANSWERS GRADED A+
◍ Which shape indicates the data flow in the flow diagram?.
Answer: single solid line with an arrow
◍ What are the advantages of the conducting dynamic code analysis?.
Answer: tests a specific operational deployment
◍ Which key deliverable occurs during post-release support?.
Answer: third-party reviews
◍ Which software security testing technique tests the software from an
external perspective?.
Answer: black box
◍ Which business function of OpenSAMM is associated with the following
core practices, verification?.
Answer: code review
◍ What is black box testing?.
Answer: tests from an external perspective with no prior knowledge of the
software
◍ What are scans that require software to log onto a system to scan it?.
Answer: authenticated scans
◍ What are the goals of listing the third party software in the SDL
deliverable?.
Answer: identify dependence on unmanaged software
◍ What are the advantages of the conducting manual source code review?.
Answer: requires no supporting technology
◍ What are scans to exploit a vulnerability when it is identified?.
, Answer: intrusive target search
◍ A new application is released, and users perform initial testing on the
application.Which type of testing are the users performing?.
Answer: Beta testing
◍ What SDL security assessment deliverable is used as an input to an SDL
architecture process?.
Answer: threat profile
◍ What is the primary task of the PIA process?.
Answer: to determine the need in the system, along with an initial definition
of the problem to be solved.
◍ Which post-release support activity defines the process to communicate,
identify, and alleviate security threats?.
Answer: PRSA1: External vulnerability disclosure response
◍ What testing tests with no prior knowledge of the software? During this
phase, only binary executable or intermediate byte code is analyzed..
Answer: black box
◍ Which post-release support activity should be completed when companies
are joining together?.
Answer: Security architectural reviews
◍ Five steps of threat modeling are:.
Answer: identify security objectives, survey the application, decompose it,
identify threats, and identify vulnerabilities.
◍ What is phase four of the SDL?.
Answer: A4 Design and Development CONT
◍ What tool is a self-managed, automatic code review product?.
Answer: SonarQube
◍ What are scans that target security issues that are found outside the
firewall?.
Answer: external scans
QUESTIONS WITH ANSWERS GRADED A+
◍ Which shape indicates the data flow in the flow diagram?.
Answer: single solid line with an arrow
◍ What are the advantages of the conducting dynamic code analysis?.
Answer: tests a specific operational deployment
◍ Which key deliverable occurs during post-release support?.
Answer: third-party reviews
◍ Which software security testing technique tests the software from an
external perspective?.
Answer: black box
◍ Which business function of OpenSAMM is associated with the following
core practices, verification?.
Answer: code review
◍ What is black box testing?.
Answer: tests from an external perspective with no prior knowledge of the
software
◍ What are scans that require software to log onto a system to scan it?.
Answer: authenticated scans
◍ What are the goals of listing the third party software in the SDL
deliverable?.
Answer: identify dependence on unmanaged software
◍ What are the advantages of the conducting manual source code review?.
Answer: requires no supporting technology
◍ What are scans to exploit a vulnerability when it is identified?.
, Answer: intrusive target search
◍ A new application is released, and users perform initial testing on the
application.Which type of testing are the users performing?.
Answer: Beta testing
◍ What SDL security assessment deliverable is used as an input to an SDL
architecture process?.
Answer: threat profile
◍ What is the primary task of the PIA process?.
Answer: to determine the need in the system, along with an initial definition
of the problem to be solved.
◍ Which post-release support activity defines the process to communicate,
identify, and alleviate security threats?.
Answer: PRSA1: External vulnerability disclosure response
◍ What testing tests with no prior knowledge of the software? During this
phase, only binary executable or intermediate byte code is analyzed..
Answer: black box
◍ Which post-release support activity should be completed when companies
are joining together?.
Answer: Security architectural reviews
◍ Five steps of threat modeling are:.
Answer: identify security objectives, survey the application, decompose it,
identify threats, and identify vulnerabilities.
◍ What is phase four of the SDL?.
Answer: A4 Design and Development CONT
◍ What tool is a self-managed, automatic code review product?.
Answer: SonarQube
◍ What are scans that target security issues that are found outside the
firewall?.
Answer: external scans