Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 41 pages
Exam (elaborations)

WGU D487 SECURE SOFTWARE DESIGN EXAM 2026/2027 | 200 Prep Questions & Answers with Rationales | OA & Pre-Assessment Practice | Pass Guaranteed - A+ Graded

Document preview thumbnail
Preview 4 out of 41 pages

Pass the WGU D487 Secure Software Design OA and Pre-Assessment with this complete 2026/2027 test bank featuring 200 prep questions, correct answers, and detailed rationales. This A+ Graded resource covers all key domains including secure design principles (least privilege, defense in depth), threat modeling (STRIDE, DREAD, PASTA), the Secure Development Lifecycle (SDL), risk assessment, and security testing (SAST, DAST) . Each answer is verified and aligned with the latest WGU course blueprint and OWASP standards . Perfect for students seeking comprehensive OA and Pre-Assessment practice. With our Pass Guarantee, you can study with confidence. Download your complete WGU D487 Exam Prep Test Bank instantly!

Content preview

WGU D487 Secure Software Design Examination 200 Questions | Graded A+




WGU D487 SECURE SOFTWARE DESIGN EXAM
200 Prep Questions and Correct Answers with Rationales for OA and Pre-Assessment Practice Plus
2026/2027 Edition | Aligned with WGU Secure Software Design Course Competencies


SECTION 1: Secure Software Design Principles and Concepts (Q1-Q30)

CIA Triad, IAAA, Defense-in-Depth, Principle of Least Privilege, Attack Surface, and Zero Trust

Q1: An e-commerce app processes credit card data. Which CIA component is violated when an attacker intercepts
payment data in transit?
A. A. Integrity
B. B. Availability
C. C. Confidentiality, unauthorized parties access sensitive data **[CORRECT]**
D. D. Accountability
Correct Answer: C
Rationale: Confidentiality ensures data is accessible only to authorized parties. Intercepting payment data is a direct violation.
WGU D487 establishes CIA as foundational.


Q2: A hospital EHR goes offline 12 hours from ransomware. Which CIA component PRIMARILY compromised?
A. A. Confidentiality
B. B. Integrity
C. C. Availability, authorized users cannot access the system **[CORRECT]**
D. D. Both equally
Correct Answer: C
Rationale: Availability ensures access when needed. Inaccessibility is the primary impact described. WGU D487 tests identifying the
primarily affected CIA component.


Q3: A financial app shows balance 5000 dollars but database holds 50000 dollars after attacker modification. Which
principle violated?
A. A. Confidentiality
B. B. Integrity, data was unauthorizedly modified **[CORRECT]**
C. C. Availability
D. D. Non-repudiation
Correct Answer: B
Rationale: Integrity ensures data accuracy. Modifying a balance during write is clear integrity violation. WGU D487 emphasizes
integrity violations in financial systems.


Q4: In IAAA, which occurs FIRST when a user logs in?
A. A. Authorization
B. B. Accountability
C. C. Identification, claiming who the user is **[CORRECT]**
D. D. Authentication
Correct Answer: C
Rationale: Identification is first: claiming identity. Then authentication verifies. WGU D487 teaches: Identification, Authentication,
Authorization, Accountability sequence.


WGU D487 Secure Software Design | OA and Pre-Assessment Practice Page 1

,WGU D487 Secure Software Design Examination 200 Questions | Graded A+




Q5: MFA requiring password, token, and biometric implements which IAAA component?
A. A. Identification
B. B. Authentication, verifying identity through multiple factors **[CORRECT]**
C. C. Authorization
D. D. Accountability
Correct Answer: B
Rationale: MFA implements authentication through multiple factors: something you know, have, are. WGU D487 distinguishes
identification from authentication.


Q6: An app grants admin rights after role change but session retains read access until re-login. This exemplifies?
A. A. Least Privilege
B. B. Separation of Duties
C. C. Defense-in-Depth
D. D. Fail-Safe Defaults, defaulting to most restrictive access **[CORRECT]**
Correct Answer: D
Rationale: Fail-safe defaults default to most restrictive when correct level is uncertain. WGU D487 tests distinguishing this from
related principles.


Q7: Each microservice has dedicated account with only necessary permissions. Which principle?
A. A. Least Privilege, minimizing each service permissions **[CORRECT]**
B. B. Separation of Duties
C. C. Defense-in-Depth
D. D. Zero Trust
Correct Answer: A
Rationale: Least Privilege gives only minimum necessary permissions. WGU D487 emphasizes this as foundational for all
architectures.


Q8: Firewalls, IDS, encryption, access controls, and training together represent?
A. A. Attack Surface Minimization
B. B. Defense-in-Depth, multiple overlapping controls **[CORRECT]**
C. C. Zero Trust
D. D. Least Privilege
Correct Answer: B
Rationale: Defense-in-Depth uses multiple security layers representing different protective layers. WGU D487 emphasizes this is a
strategy, not a single control.


Q9: Removing unused endpoints, disabling debug mode, moving secrets server-side represents?
A. A. Defense-in-Depth
B. B. Attack Surface Minimization, reducing entry points **[CORRECT]**
C. C. Zero Trust
D. D. Least Privilege
Correct Answer: B
Rationale: Attack Surface Minimization reduces exposed entry points. WGU D487 distinguishes this from adding defensive layers.


Q10: In Zero Trust, which is MOST accurate about internal traffic?


WGU D487 Secure Software Design | OA and Pre-Assessment Practice Page 2

,WGU D487 Secure Software Design Examination 200 Questions | Graded A+



A. A. Trusted within firewall
B. B. Partially trusted by subnet
C. C. Never implicitly trusted, verified at every point **[CORRECT]**
D. D. Trusted after first auth
Correct Answer: C
Rationale: Zero Trust: never trust, always verify. No traffic is implicitly trusted regardless of origin. WGU D487 emphasizes this
eliminates trusted internal network concept.


Q11: Requiring different people to create vendors and approve payments enforces?
A. A. Least Privilege
B. B. Separation of Duties, dividing critical operations **[CORRECT]**
C. C. Defense-in-Depth
D. D. Attack Surface Minimization
Correct Answer: B
Rationale: SoD ensures no single person completes a critical transaction end-to-end. WGU D487 stresses SoD prevents insider
threats and fraud.


Q12: Which BEST exemplifies Least Privilege?
A. A. All developers get admin access
B. B. Read-only DB account for reporting module **[CORRECT]**
C. C. Same service account for all microservices
D. D. End users get root
Correct Answer: B
Rationale: Read-only account has exactly needed permissions. Other options grant excessive privileges. WGU D487 emphasizes
least privilege applies to service accounts too.


Q13: Which approach is MOST consistent with Zero Trust?
A. A. Strong perimeter firewall trusting internal traffic
B. B. Micro-segmentation with per-service authentication **[CORRECT]**
C. C. Full access after VPN
D. D. Single auth at boundary
Correct Answer: B
Rationale: Zero Trust requires verifying every request. Micro-segmentation ensures no implicit trust. WGU D487 emphasizes
continuous verification over perimeter defenses.


Q14: A login page allows unlimited attempts. Which CIA component MOST at risk?
A. A. Confidentiality, because brute-force could compromise passwords **[CORRECT]**
B. B. Availability
C. C. Integrity
D. D. Both equally
Correct Answer: A
Rationale: Unlimited attempts threaten confidentiality through brute-force. WGU D487 teaches identifying which CIA component
is threatened guides countermeasure selection.


Q15: Which BEST describes the CIA-IAAA relationship?
A. A. IAAA is a CIA subset


WGU D487 Secure Software Design | OA and Pre-Assessment Practice Page 3

, WGU D487 Secure Software Design Examination 200 Questions | Graded A+



B. B. They are independent
C. C. IAAA supports CIA by managing entity access to data **[CORRECT]**
D. D. CIA replaces IAAA
Correct Answer: C
Rationale: IAAA supports CIA through access management. They are complementary frameworks. WGU D487 teaches these as
interconnected.


Q16: Logging all user actions with timestamps and IDs implements which IAAA component?
A. A. Identification
B. B. Authentication
C. C. Authorization
D. D. Accountability, tracing actions to users **[CORRECT]**
Correct Answer: D
Rationale: Logging for traceability implements accountability. WGU D487 emphasizes audit logging achieves accountability and
non-repudiation.


Q17: Legacy app uses plaintext DB comms and unencrypted local storage. Best strategy?
A. A. WAF
B. B. Defense-in-Depth: encryption in transit and at rest **[CORRECT]**
C. C. Remove the DB
D. D. Zero Trust re-auth
Correct Answer: B
Rationale: Defense-in-Depth adds layered controls. TLS for transit and encryption for cached data address both vulnerabilities.
WGU D487 teaches complementary controls for different classes.


Q18: Which is TRUE about Zero Trust per NIST SP 800-207?
A. A. Eliminates firewalls
B. B. Assumes the network is not inherently trustworthy **[CORRECT]**
C. C. Requires microservices
D. D. Only applies to cloud
Correct Answer: B
Rationale: NIST SP 800-207 defines Zero Trust as assuming no automatic trust. WGU D487 aligns with NIST standards on this
fundamental principle.


Q19: Session tokens in local storage stolen via XSS. Which TWO principles violated?
A. A. Confidentiality and Availability
B. B. Integrity and Accountability
C. C. Confidentiality and Integrity **[CORRECT]**
D. D. Availability and Accountability
Correct Answer: C
Rationale: Token theft violates confidentiality and potentially integrity if attacker modifies data. WGU D487 emphasizes
cascading CIA impacts from single vulnerabilities.


Q20: Backup operator has full admin access. Which principle guides remediation?
A. A. Separation of Duties
B. B. Least Privilege, needing only backup permissions **[CORRECT]**


WGU D487 Secure Software Design | OA and Pre-Assessment Practice Page 4

Document information

Uploaded on
August 25, 2026
Number of pages
41
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$30.50

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
NURSEEXAMITY
3.4
(105)
Sold
558
Followers
275
Items
6673
Last sold
1 day ago




Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions