WGU D487 SECURE SW DESIGN
MOST TESTED QUESTIONS
AND ANSWERS
What term is the environment in which the product will operate and potential
threats in that environment? - threat profile
What phase of the SDL examines security in terms of business risks, with inputs
from the software security team and key stakeholders? - A2 Architecture Phase
In what phase of the SDL is threat modeling conducted? - A2 Architecture
Phase
What is it called when technicians identify security objectives, survey
applications, decompose applications, identify threats, and identify
vulnerabilities? - threat modeling
What is the process to pinpoint security threats and potential vulnerabilities that
will help prioritize remediation. - threat modeling
,Five steps of threat modeling are: - identify security objectives, survey the
application, decompose it, identify threats, and identify vulnerabilities.
What does STRIDE stand for? - spoofing, tampering, repudiation, information
disclosure, denial of service, and elevation of privilege
What does PASTA stand for? - process of attack simulation and threat analysis
How should you rank an organization's threats? - based on their probability and
damage potential.
What does DREAD stand for? - damage potential, reproducibility,
exploitability, affected users, and discoverability
What is a weakness that can be exploited? - vulnerability
What is a unified conceptual framework for security auditing? - Trike Threat
Model
What is the path an attacker can take to exploit a vulnerability? - threat vector
, What term is a process that evaluates issues and privacy impact rating in
relation to the privacy of personally identifiable information in the software? -
privacy impact assessment
What term helps to determine the actual cost of the product from different
perspectives? - product risk profile
What term is a table that lists all of the security requirements - requirement
traceability matrix
What are the two deliverables of the Architecture phase of the SDL? - threat
modeling artifacts, policy compliance analysis
What SDL security assessment deliverable is used as an input to an SDL
architecture process? - threat profile
What is alpha level testing? - testing done by the developers themselves
What is beta level testing? - testing done by those not familiar with the actual
development of the system
What is black box testing? - tests from an external perspective with no prior
knowledge of the software
MOST TESTED QUESTIONS
AND ANSWERS
What term is the environment in which the product will operate and potential
threats in that environment? - threat profile
What phase of the SDL examines security in terms of business risks, with inputs
from the software security team and key stakeholders? - A2 Architecture Phase
In what phase of the SDL is threat modeling conducted? - A2 Architecture
Phase
What is it called when technicians identify security objectives, survey
applications, decompose applications, identify threats, and identify
vulnerabilities? - threat modeling
What is the process to pinpoint security threats and potential vulnerabilities that
will help prioritize remediation. - threat modeling
,Five steps of threat modeling are: - identify security objectives, survey the
application, decompose it, identify threats, and identify vulnerabilities.
What does STRIDE stand for? - spoofing, tampering, repudiation, information
disclosure, denial of service, and elevation of privilege
What does PASTA stand for? - process of attack simulation and threat analysis
How should you rank an organization's threats? - based on their probability and
damage potential.
What does DREAD stand for? - damage potential, reproducibility,
exploitability, affected users, and discoverability
What is a weakness that can be exploited? - vulnerability
What is a unified conceptual framework for security auditing? - Trike Threat
Model
What is the path an attacker can take to exploit a vulnerability? - threat vector
, What term is a process that evaluates issues and privacy impact rating in
relation to the privacy of personally identifiable information in the software? -
privacy impact assessment
What term helps to determine the actual cost of the product from different
perspectives? - product risk profile
What term is a table that lists all of the security requirements - requirement
traceability matrix
What are the two deliverables of the Architecture phase of the SDL? - threat
modeling artifacts, policy compliance analysis
What SDL security assessment deliverable is used as an input to an SDL
architecture process? - threat profile
What is alpha level testing? - testing done by the developers themselves
What is beta level testing? - testing done by those not familiar with the actual
development of the system
What is black box testing? - tests from an external perspective with no prior
knowledge of the software