Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 142 pages
Exam (elaborations)

WGU D487 SECURE SOFTWARE DESIGN OBJECTIVE ASSESSMENT (OA) EXAM BANK VERIFIED QUESTIONS WITH EXPERT RATIONALES LATEST 2026 UPDATE | ACCURATE & VERIFIED

Document preview thumbnail
Preview 4 out of 142 pages

Master the WGU D487 Secure Software Design Objective Assessment with this comprehensive, expert-verified exam bank featuring 350+ accurate practice questions with detailed rationales. Covering every essential domain including Secure Software Development Lifecycle (SDLC), Threat Modeling (STRIDE, DREAD, PASTA), Risk Management, Secure Coding Practices, Security Testing (SAST, DAST, Penetration Testing, Fuzzing), Security Frameworks (BSIMM, OWASP SAMM, NIST CSF, ISO 27001), DevSecOps, Agile Security, and Security Architecture principles. Each question includes correct answers with in-depth explanations to reinforce understanding and guarantee exam success. Perfect for WGU students, software developers, security architects, and IT professionals pursuing secure software design certification or advancing their cybersecurity careers. Updated with the latest 2026 content and verified by subject matter experts for 100% accuracy. Pass your WGU D487 OA with confidence using this ultimate test preparation resource.

Content preview

WGU D487 SECURE SOFTWARE DESIGN OBJECTIVE
ASSESSMENT (OA) EXAM BANK VERIFIED QUESTIONS WITH
EXPERT RATIONALES LATEST 2026 UPDATE |
ACCURATE & VERIFIED
SECTION 1: SECURE SOFTWARE DEVELOPMENT LIFECYCLE (SDLC) (Questions 1–50)
Q1. The ______ report should provide progress against privacy requirements
provided in earlier phases and note any new laws/regulations to roadmap.

A. Security Testing Report
B. Privacy Compliance Report
C. Remediation Dashboard
D. Final Privacy Review

Correct Answer: B
Rationale: The Privacy Compliance Report tracks progress against earlier privacy
requirements and documents any new laws or regulations that may impact the
software development roadmap[reference:0].



Q2. A findings summary should be prepared for manual code review,
static/dynamic
analysis, pen testing, and fuzzing. These are:

A. Remediation Reports
B. Final Security Reviews
C. Security Testing Reports
D. Metrics Templates

Correct Answer: C
Rationale: Security Testing Reports summarize the findings from various testing
methods including manual code review, static/dynamic analysis, penetration


1

,testing, and fuzzing[reference:1].



Q3. A ______ report/dashboard should be prepared and updated to show
technical
security posture and risk.

A. Security Metrics
B. Compliance Dashboard
C. Remediation Dashboard
D. Threat Modeling Report

Correct Answer: C
Rationale: A Remediation Dashboard is prepared and updated to show the
current
technical security posture and risk levels, tracking progress on identified
vulnerabilities[reference:2].



Q4. What is the primary goal of secure software design?

A) To enhance user experience
B) To mitigate security risks throughout the software lifecycle
C) To reduce development time
D) To comply with regulatory requirements

Correct Answer: B
Rationale: The primary goal of secure software design is to mitigate security
risks throughout the software development lifecycle by building security into
the design from the outset[reference:3][reference:4].



Q5. Which SDLC phase is most critical for integrating security?

2

,A) Testing
B) Requirements gathering
C) Deployment
D) Maintenance

Correct Answer: B
Rationale: Early integration in the requirements phase ensures security is built
into the software from the beginning. Addressing security in requirements is
far more cost-effective than fixing vulnerabilities later[reference:5].



Q6. What is the primary benefit of performing security reviews early in the
SDLC?

A) Reduced development time
B) Lower cost of fixing vulnerabilities
C) Increased code complexity
D) Fewer developers needed

Correct Answer: B
Rationale: Identifying and fixing vulnerabilities early in the SDLC is
significantly less expensive than fixing them later[reference:6].



Q7. Which of the following is a key deliverable in the Security Development
Lifecycle (SDL)?

A) User Interface Design Document
B) Privacy Compliance Report
C) Marketing Strategy
D) Project Budget


3

, Correct Answer: B
Rationale: The Privacy Compliance Report is a key SDL deliverable that tracks
progress against privacy requirements[reference:7].



Q8. In the Ship (A5) phase of the security development cycle, the team must
verify that all security mandates have been met before release. This activity is
best described as:

A) Vulnerability scanning
B) Code-assisted penetration testing
C) Open-source licensing review
D) A5 policy compliance analysis

Correct Answer: D
Rationale: A5 policy compliance analysis ensures that all security mandates and
compliance activities have been met at each SDL phase before
release[reference:8].



Q9. During which phase of the SDLC should threat modeling be performed?

A) Deployment
B) Maintenance
C) Design
D) Testing

Correct Answer: C
Rationale: Threat modeling should be performed during the design phase to
identify potential security threats and vulnerabilities early when they are
easier and cheaper to address[reference:9].




4

Document information

Uploaded on
July 16, 2026
Number of pages
142
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers
$24.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
PrepMaster
4.8
(312)
Sold
307
Followers
19
Items
3031
Last sold
1 hour ago


Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions