Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 45 pages
Exam (elaborations)

WGU D487 Secure Software Design Practice Questions and Correct Answers | Comprehensive Exam Prep

Document preview thumbnail
Preview 4 out of 45 pages

Prepare for the WGU D487 Secure Software Design Exam with this comprehensive practice question guide. It includes multiple-choice questions with accurate answers and detailed rationales covering secure software development principles, security architecture, threat modeling, secure coding practices, vulnerability management, authentication and authorization, encryption concepts, software security testing, risk assessment, and secure design methodologies. An excellent resource for students preparing for WGU assessments and strengthening secure software engineering skills.

Content preview

WGU D487 SECURE SOFTWARE DESIGN
QUESTIONS AND CORRECT AND CORRECT
ANSWERS (VERIFIED ANSWERS) Q&A 2026-
2027|INSTANT DOWNLOAD
1. Which principle ensures that software components receive
only the permissions necessary to perform their tasks?
A. Defense in depth
B. Least privilege
C. Separation of duties
D. Fail-open design
Correct Answer: B. Least privilege
Rationale: The principle of least privilege restricts users,
processes, and applications to only the access rights required to
complete their functions, reducing attack opportunities.


2. What is the primary goal of secure software design?
A. Increase software complexity
B. Eliminate all testing requirements
C. Reduce vulnerabilities throughout the software lifecycle
D. Improve application appearance
Correct Answer: C. Reduce vulnerabilities throughout the
software lifecycle

,Rationale: Secure software design focuses on preventing
vulnerabilities through planning, architecture, coding practices,
testing, and maintenance.


3. Which security practice involves considering security
requirements during the initial design phase?
A. Security by design
B. Patch management
C. Incident response
D. Penetration testing
Correct Answer: A. Security by design
Rationale: Security by design integrates security controls from
the beginning instead of adding them after development.


4. What type of vulnerability occurs when an application
executes unintended commands through user input?
A. Buffer overflow
B. Injection attack
C. Cross-site request forgery
D. Race condition
Correct Answer: B. Injection attack
Rationale: Injection vulnerabilities occur when untrusted input
is interpreted as commands or queries by an application.

,5. Which OWASP vulnerability involves inserting malicious
scripts into web pages viewed by users?
A. SQL injection
B. Cross-site scripting (XSS)
C. Broken authentication
D. Security misconfiguration
Correct Answer: B. Cross-site scripting (XSS)
Rationale: XSS allows attackers to execute malicious scripts in
another user’s browser.


6. What is the purpose of input validation in secure software
development?
A. Improve application graphics
B. Verify user input meets expected requirements
C. Increase database size
D. Remove authentication requirements
Correct Answer: B. Verify user input meets expected
requirements
Rationale: Input validation prevents malicious or unexpected
data from being processed by the application.

, 7. Which software development model integrates security
activities throughout the development process?
A. Waterfall only
B. Secure Software Development Lifecycle (SSDLC)
C. Rapid prototyping only
D. Hardware lifecycle model
Correct Answer: B. Secure Software Development Lifecycle
(SSDLC)
Rationale: SSDLC incorporates security practices during
planning, design, coding, testing, deployment, and
maintenance.


8. What security concept assumes systems will eventually fail
and prepares controls to limit damage?
A. Zero trust
B. Defense in depth
C. Obfuscation
D. Open design
Correct Answer: B. Defense in depth
Rationale: Defense in depth uses multiple security layers so
that one failed control does not compromise the entire system.


9. Which method helps identify vulnerabilities by analyzing
application source code?

Document information

Uploaded on
July 21, 2026
Number of pages
45
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers
$25.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
docsmartpass
5.0
(3)
Sold
12
Followers
6
Items
1750
Last sold
4 days ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions