WGU D487 OA 2 & 3 HIGH-YIELD QUALITY
IMPROVEMENT, PATIENT SAFETY, AND
HEALTHCARE REGULATIONS SUMMARY 2026
◉ What are the three areas of focus in secure software
requirements?
Answer: Gathering the software requirements, data classification,
and managing data protection requirements
◉ During what phase of SDL is an initial project outline for security
milestones developed and integrated into the development project
schedule?
Answer: A1 Security Assessment
◉ What term means requirements that describe what the system
will do and its core purpose?
Answer: functional requirements
◉ What term means requirements that describe any constraints or
restrictions on a design but do not impact the core purpose of the
system
Answer: non-functional requirements
,◉ What term is a process that evaluates issues and privacy impact
rating in relation to the privacy of personally identifiable
information in the software?
Answer: privacy impact assessment
◉ What term helps to determine the actual cost of the product from
different perspectives?
Answer: product risk profile
◉ What term is a table that lists all of the security requirements
Answer: requirement traceability matrix
◉ What term is the environment in which the product will operate
and potential threats in that environment?
Answer: threat profile
◉ What phase of the SDL examines security in terms of business
risks, with inputs from the software security team and key
stakeholders?
Answer: A2 Architecture Phase
◉ In what phase of the SDL is threat modeling conducted?
Answer: A2 Architecture Phase
, ◉ What is it called when technicians identify security objectives,
survey applications, decompose applications, identify threats, and
identify vulnerabilities?
Answer: threat modeling
◉ What is the process to pinpoint security threats and potential
vulnerabilities that will help prioritize remediation.
Answer: threat modeling
◉ Five steps of threat modeling are:
Answer: identify security objectives, survey the application,
decompose it, identify threats, and identify vulnerabilities.
◉ What does STRIDE stand for?
Answer: spoofing, tampering, repudiation, information disclosure,
denial of service, and elevation of privilege
◉ What does PASTA stand for?
Answer: process of attack simulation and threat analysis
◉ How should you rank an organization's threats?
Answer: based on their probability and damage potential.
IMPROVEMENT, PATIENT SAFETY, AND
HEALTHCARE REGULATIONS SUMMARY 2026
◉ What are the three areas of focus in secure software
requirements?
Answer: Gathering the software requirements, data classification,
and managing data protection requirements
◉ During what phase of SDL is an initial project outline for security
milestones developed and integrated into the development project
schedule?
Answer: A1 Security Assessment
◉ What term means requirements that describe what the system
will do and its core purpose?
Answer: functional requirements
◉ What term means requirements that describe any constraints or
restrictions on a design but do not impact the core purpose of the
system
Answer: non-functional requirements
,◉ What term is a process that evaluates issues and privacy impact
rating in relation to the privacy of personally identifiable
information in the software?
Answer: privacy impact assessment
◉ What term helps to determine the actual cost of the product from
different perspectives?
Answer: product risk profile
◉ What term is a table that lists all of the security requirements
Answer: requirement traceability matrix
◉ What term is the environment in which the product will operate
and potential threats in that environment?
Answer: threat profile
◉ What phase of the SDL examines security in terms of business
risks, with inputs from the software security team and key
stakeholders?
Answer: A2 Architecture Phase
◉ In what phase of the SDL is threat modeling conducted?
Answer: A2 Architecture Phase
, ◉ What is it called when technicians identify security objectives,
survey applications, decompose applications, identify threats, and
identify vulnerabilities?
Answer: threat modeling
◉ What is the process to pinpoint security threats and potential
vulnerabilities that will help prioritize remediation.
Answer: threat modeling
◉ Five steps of threat modeling are:
Answer: identify security objectives, survey the application,
decompose it, identify threats, and identify vulnerabilities.
◉ What does STRIDE stand for?
Answer: spoofing, tampering, repudiation, information disclosure,
denial of service, and elevation of privilege
◉ What does PASTA stand for?
Answer: process of attack simulation and threat analysis
◉ How should you rank an organization's threats?
Answer: based on their probability and damage potential.