1|Page
WGU D487 PRE-ASSESSMENT SECURE
SOFTWARE DESIGN (KEO1) (PKEO) ACTUAL
EXAM PREP 2026 ALL QUESTIONS AND
CORRECT DETAILED ANSWERS ALREADY A
GRADED WITH EXPERT FEEDBACK |NEW AND
REVISED
A software security team member has created data flow diagrams,
chosen the STRIDE methodology to perform threat reviews, and created
the security assessment for the new product. Which category of secure
software best practices did the team member perform? - ANSWER-
Architecture analysis
Team members are being introduced during sprint zero in the project
kickoff meeting. The person being introduced will be a facilitator, will
try to remove roadblocks and ensure the team is communicating freely,
and will be responsible for facilitating all scrum ceremonies. Which role
is the team member playing? - ANSWER- Scrum master
The new product standards state that all traffic must be secure and
encrypted. What is the name for this secure coding practice? -
ANSWER- Communication security
Which DREAD category is based on how easily a threat exploit can be
repeated? - ANSWER- Reproducibility
1|Page
,2|Page
Which mitigation technique can be used to fight against a data tampering
threat? - ANSWER- Digital signatures
What is a countermeasure to the web application security frame (ASF)
configuration management threat category? - ANSWER- Compliance
requirement
Which type of requirement specifies that file formats the application
sends to financial institutions must be certified every four years? -
ANSWER- Compliance requirement
Which type of requirement specifies that credit card numbers displayed
in the application will be masked so they only show the last four digits?
- ANSWER- Privacy requirement
Which type of requirement specifies that user passwords will require a
minimum of 8 characters and must include at least one uppercase
character, one number, and one special character? - ANSWER- Security
requirement
Which type of requirement specifies that credit card numbers are
designated as highly sensitive confidential personal information? -
ANSWER- Data classification requirement
Which privacy impact statement requirement type defines how personal
information is protected on devices used by more than a single
associate? - ANSWER- Privacy control requirements
2|Page
,3|Page
In which step of the PASTA threat modeling methodology does design
flaw analysis take place? - ANSWER- Vulnerability and weakness
analysis
Which privacy impact statement requirement type defines who has
access to personal information within the product? - ANSWER- Access
requirements
Which security assessment deliverable defines milestones that will be
met during each phase of the project, merged into the product
development schedule? - ANSWER- SDL project outline
Which architecture deliverable identifies whether the product adheres to
organization security rules? - ANSWER- Policy compliance analysis
Which threat modeling process identifies threats to each individual
object in a data flow diagram? - ANSWER- STRIDE-per-element
The DREAD methodology has been used to classify an identified exploit
where:
the attacker could log in as an administrator (damage potential)
the attacker could log in at any time (reproducibility)
almost anybody could perform the attack (exploitability)
all system users could be affected (affected users)
3|Page
, 4|Page
any person who knows how to open dev tools in a browser could find
the vulnerability (discoverability)
Which rating should be assigned to the exploit after performing an
analysis using a ternary ranking scale where high risk = 3 points,
medium risk = 2 points, and low risk = 1 point? - ANSWER- High risk
What is the recommended way to mitigate a threat identified during
threat modeling? - ANSWER- Apply a standard accepted
countermeasure
The organization's testing team has created a catalog of test cases using
the source code and design documentation of the new product. Each test
case will be executed for each user role in the new product. Which type
of security testing technique is being performed? - ANSWER- White-
box
Security team members have been instructed to document which
developers and analysts will perform product testing and which tools
they will use. Which step of the security test plan is being performed? -
ANSWER- Identify internal resources
Security team members have been instructed to document how many
users will access the new product and what roles those users will play.
Which step of the security test plan is being performed? - ANSWER-
Define the user community
The project team received a SonarQube report of their most recent stage
deployment that contains 15 vulnerabilities that must be fixed before the
4|Page
WGU D487 PRE-ASSESSMENT SECURE
SOFTWARE DESIGN (KEO1) (PKEO) ACTUAL
EXAM PREP 2026 ALL QUESTIONS AND
CORRECT DETAILED ANSWERS ALREADY A
GRADED WITH EXPERT FEEDBACK |NEW AND
REVISED
A software security team member has created data flow diagrams,
chosen the STRIDE methodology to perform threat reviews, and created
the security assessment for the new product. Which category of secure
software best practices did the team member perform? - ANSWER-
Architecture analysis
Team members are being introduced during sprint zero in the project
kickoff meeting. The person being introduced will be a facilitator, will
try to remove roadblocks and ensure the team is communicating freely,
and will be responsible for facilitating all scrum ceremonies. Which role
is the team member playing? - ANSWER- Scrum master
The new product standards state that all traffic must be secure and
encrypted. What is the name for this secure coding practice? -
ANSWER- Communication security
Which DREAD category is based on how easily a threat exploit can be
repeated? - ANSWER- Reproducibility
1|Page
,2|Page
Which mitigation technique can be used to fight against a data tampering
threat? - ANSWER- Digital signatures
What is a countermeasure to the web application security frame (ASF)
configuration management threat category? - ANSWER- Compliance
requirement
Which type of requirement specifies that file formats the application
sends to financial institutions must be certified every four years? -
ANSWER- Compliance requirement
Which type of requirement specifies that credit card numbers displayed
in the application will be masked so they only show the last four digits?
- ANSWER- Privacy requirement
Which type of requirement specifies that user passwords will require a
minimum of 8 characters and must include at least one uppercase
character, one number, and one special character? - ANSWER- Security
requirement
Which type of requirement specifies that credit card numbers are
designated as highly sensitive confidential personal information? -
ANSWER- Data classification requirement
Which privacy impact statement requirement type defines how personal
information is protected on devices used by more than a single
associate? - ANSWER- Privacy control requirements
2|Page
,3|Page
In which step of the PASTA threat modeling methodology does design
flaw analysis take place? - ANSWER- Vulnerability and weakness
analysis
Which privacy impact statement requirement type defines who has
access to personal information within the product? - ANSWER- Access
requirements
Which security assessment deliverable defines milestones that will be
met during each phase of the project, merged into the product
development schedule? - ANSWER- SDL project outline
Which architecture deliverable identifies whether the product adheres to
organization security rules? - ANSWER- Policy compliance analysis
Which threat modeling process identifies threats to each individual
object in a data flow diagram? - ANSWER- STRIDE-per-element
The DREAD methodology has been used to classify an identified exploit
where:
the attacker could log in as an administrator (damage potential)
the attacker could log in at any time (reproducibility)
almost anybody could perform the attack (exploitability)
all system users could be affected (affected users)
3|Page
, 4|Page
any person who knows how to open dev tools in a browser could find
the vulnerability (discoverability)
Which rating should be assigned to the exploit after performing an
analysis using a ternary ranking scale where high risk = 3 points,
medium risk = 2 points, and low risk = 1 point? - ANSWER- High risk
What is the recommended way to mitigate a threat identified during
threat modeling? - ANSWER- Apply a standard accepted
countermeasure
The organization's testing team has created a catalog of test cases using
the source code and design documentation of the new product. Each test
case will be executed for each user role in the new product. Which type
of security testing technique is being performed? - ANSWER- White-
box
Security team members have been instructed to document which
developers and analysts will perform product testing and which tools
they will use. Which step of the security test plan is being performed? -
ANSWER- Identify internal resources
Security team members have been instructed to document how many
users will access the new product and what roles those users will play.
Which step of the security test plan is being performed? - ANSWER-
Define the user community
The project team received a SonarQube report of their most recent stage
deployment that contains 15 vulnerabilities that must be fixed before the
4|Page