Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 58 pages
Exam (elaborations)

WGU D487 SECURE SOFTWARE DESIGN OBJECTIVE ASSESSMENT ACTUAL EXAM PREP 2026 ALL QUESTIONS AND CORRECT DETAILED ANSWERS WITH RATIONALES ALREADY A GRADED WITH EXPERT FEEDBACK |NEW AND REVISED

Document preview thumbnail
Preview 4 out of 58 pages

WGU D487 SECURE SOFTWARE DESIGN OBJECTIVE ASSESSMENT ACTUAL EXAM PREP 2026 ALL QUESTIONS AND CORRECT DETAILED ANSWERS WITH RATIONALES ALREADY A GRADED WITH EXPERT FEEDBACK |NEW AND REVISED

Content preview

1|Page



WGU D487 SECURE SOFTWARE DESIGN
OBJECTIVE ASSESSMENT ACTUAL EXAM PREP
2026 ALL QUESTIONS AND CORRECT
DETAILED ANSWERS WITH RATIONALES
ALREADY A GRADED WITH EXPERT
FEEDBACK |NEW AND REVISED



1. What is the primary goal of secure software design?
A. Maximize software performance and efficiency
B. Protect applications from security threats throughout the SDLC
C. Reduce overall development time and costs
D. Enhance the user interface and experience
Rationale: Secure software design focuses on mitigating
vulnerabilities throughout the software development lifecycle (SDLC).
While performance, cost, and user experience are important
considerations, the primary goal is to protect applications from
security threats.


2. Which SDLC phase is most critical for integrating security?
A. Testing
B. Requirements gathering
C. Deployment
D. Maintenance
Rationale: Early integration of security in the requirements gathering
phase ensures security is built into the application from the beginning,

,2|Page


following NIST guidelines. Addressing security late in the SDLC is
more costly and less effective.


3. What is the purpose of threat modeling in secure software design?
A. Optimize code execution efficiency
B. Identify potential security risks and vulnerabilities
C. Increase system uptime and availability
D. Reduce hardware and infrastructure costs
Rationale: Threat modeling is a structured process to systematically
identify, quantify, and address security risks associated with an
application by analyzing its architecture, data flows, and potential
threats.


4. What does the STRIDE threat modeling acronym stand for?
A. Spoofing, Tampering, Repudiation, Information Disclosure,
Denial of Service, Elevation of Privilege
B. Spoofing, Tracking, Repudiation, Injection, Disclosure, Execution
C. Scanning, Tampering, Repudiation, Injection, Disclosure,
Exploitation
D. Spoofing, Tampering, Replay, Information Disclosure, DoS,
Escalation
Rationale: STRIDE is a Microsoft threat categorization framework
where each letter represents a threat category: Spoofing, Tampering,
Repudiation, Information Disclosure, Denial of Service, and Elevation
of Privilege.


5. Which principle mandates that users should be granted the minimum
level of access necessary to perform their job functions?

,3|Page


A. Least Privilege
B. Defense in Depth
C. Separation of Duties
D. Complete Mediation
Rationale: The Principle of Least Privilege (PoLP) mandates that any
user, process, or system should be granted the minimum levels of
access necessary to perform its authorized functions, limiting potential
damage from accidents or attacks.


6. Which security design principle advocates for multiple, layered
security controls so that if one layer fails, others remain to protect the
asset?
A. Least Privilege
B. Fail-Safe Defaults
C. Defense in Depth
D. Economy of Mechanism
Rationale: Defense in Depth employs multiple, layered security
controls (physical, network, host, application, data) so that if one layer
fails, others remain to protect the asset.


7. In the STRIDE model, which threat involves pretending to be
someone or something else?
A. Spoofing
B. Tampering
C. Repudiation
D. Elevation of Privilege
Rationale: Spoofing is the act of pretending to be someone or
something else, such as stealing a session cookie or forging an
identity. It violates the security property of authentication.

, 4|Page




8. What is the key idea behind Fail-Safe Defaults?
A. Systems should default to allowing all access
B. Access decisions should default to "deny" unless explicitly
permitted
C. Systems should continue operating during failures
D. Security controls should be optional
Rationale: Fail-Safe Defaults means that access decisions should
default to "deny" unless explicitly permitted. The system should
remain secure in the event of a failure.


9. Which risk assessment model is used to prioritize found threats based
on Damage, Reproducibility, Exploitability, Affected Users, and
Discoverability?
A. STRIDE
B. DREAD
C. PASTA
D. OCTAVE
Rationale: DREAD is a risk rating model used for quantitatively
prioritizing found threats based on five factors: Damage,
Reproducibility, Exploitability, Affected Users, and Discoverability.


10. What does the CIA Triad represent in information security?
A. Confidentiality, Integrity, Availability
B. Confidentiality, Identity, Accountability
C. Confidentiality, Integrity, Availability
D. Control, Identity, Authentication

Document information

Uploaded on
July 3, 2026
Number of pages
58
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers
$22.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
impressivetutor
4.8
(1823)
Sold
681
Followers
377
Items
3690
Last sold
2 days ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions