QUESTIONS AND CORRECT DETAILED ANSWERS (VERIFIED
ANSWERS) ALL
ANSWERED {172 Q & A} ALREADY GRADED A+ / WGU – D487
OBJECTIVE ASSESSMENT FINAL EXAM | GUARANTEED PASS |
D487 OBJECTIVE ASSESSMENT FINAL EXAM | WGU
Deployment Phase (SDLC) - ✔✔✔ Correct Answer>Security is pushed out
Design Phase (SDLC) - ✔✔✔ Correct Answer>Requirements are prepared for the
technical design
Implementation Phase - ✔✔✔ Correct Answer> The resources involved in the
application from a known resource are determined
Maintenance Phase - ✔✔✔ Correct Answer>Ongoing security monitoring is
implemented
Planning Phase of SDLC -✔✔✔ Correct Answer> vision and next steps are created
,Secure code - ✔✔✔ Correct Answer>a principle design in coding that refers to code
security best practices, safeguards, and protection against vulnerabilities
Threat modeling - ✔✔✔ Correct Answer>a structured process to protect against
vulnerabilities
What are the three core elements of security -✔✔✔ Correct Answer>confidentiality,
integrity, and availability
8 phases of the SDLC -✔✔✔ Correct Answer>planning, requirements, design,
implementation, testing, deployment, maintenance and end of life
What is software security -✔✔✔ Correct Answer>Security that deals with securing the
foundational programmatic logic of the underlying software
Which part of the CIA keeps unauthorized users from accessing confidential
information -✔✔✔ Correct Answer>Confidentiality
BSIMM -✔✔✔ Correct Answer>a study of real-world software security that allows you
to develop your software security over time
,Dynamic analysis - ✔✔✔ Correct Answer> analysis of computer software that is
performed when executing the program on a real or virtual processor in real time
Fuzz testing - ✔✔✔ Correct Answer> automated or semi-automated testing
that provides invalid, unexpected, or random data to the computer
program.
Measure model - ✔✔✔ Correct Answer>A set of data security methods that developers
take to protect against vulnerabilities
Metric model - ✔✔✔ Correct Answer> allows organizations to determine the
effectiveness of their security controls
OWASP -✔✔✔ Correct Answer>A flexible and prospective framework to build security
into your software development organization
Static analysis -✔✔✔ Correct Answer> The analysis of computer software that is
performed without executing programs
Computer Vulnerabilities and Exposures -✔✔✔ Correct Answer>A list of information
that aims to provide common names for publicly known security vulnerabilities
, What are the three primary tools basic to the SDLC - ✔✔✔ Correct Answer> Fuzz
testing, static analysis, and dynamic analysis testing
In which phase of the SDLC should the software security team be involved -✔✔✔
Correct Answer>Concept
Waterfall -✔✔✔ Correct Answer> An approach that divides the process of software
development into separate phases. The outcome of one phase acts as the input
for the next phase
Waterfall advantages -✔✔✔ Correct Answer> Splitting into different stages makes it
easier for an organization to control the development process.
Waterfall Disadvantages -✔✔✔ Correct Answer> Does not allow time for reflection or a
revision to the design
Agile - ✔✔✔ Correct Answer>Uses collaboration between self-organizing and cross-
functional teams. 4 core values and 12 principles
Agile Advantage -✔✔✔ Correct Answer>customer satisfaction through rapid,
continuous delivery of useful software