WGU D385 | Pytest & Security Unit Testing Workbook | 2026
WGU D385
Pytest & Security Unit Testing
Workbook
48 Practice Tests
Python Security, API Testing & Vulnerability Verification | 2026
Document Type: Workbook & Practice Tests
Course: WGU D385 - Pytest & Security Unit Testing
Academic Year:
Question Count: 48 Multiple-Choice Questions
Structure: 4 Sections | 12 Questions per Section
Cognitive Mix: 30% Recall | 50% Application | 20% Analysis
Question Style: 75% Scenario-Based | 25% Direct
Includes: Complete Solution Key + Grading Rubric
Aligned with 2026/2027 academic and industry standards.
Integrates modern Python security libraries, Pytest best practices, and DevSecOps workflows.
Page 1 | WGU D385 Workbook
,WGU D385 | Pytest & Security Unit Testing Workbook | 2026
Workbook Overview
This Workbook & Practice Tests guide for WGU D385 assesses mastery across four integrated
competency domains: (1) Python Security Fundamentals and Secure Coding Practices; (2) Unit Testing
Frameworks and Pytest Mastery; (3) API Testing, Automation, and Integration; and (4) Vulnerability
Verification, CI/CD Security, and 2026 Updates. The guide mirrors the cognitive demand profile of the
course: 30 percent recall, 50 percent application, and 20 percent analysis, with 75 percent scenario-based
items and 25 percent direct items.
Each question includes the correct answer and a detailed step-by-step rationale explaining the
secure-coding pattern, Pytest feature, API-testing technique, or CI/CD security control, and explicitly
identifying why each distractor represents insecure code, a broken test, or a flawed security practice.
Distractors are engineered to reflect the most consequential errors observed in Python development and
testing.
Document Structure
Part Content Questions
Part 1 Examination Questions (48 Items) Q1 - Q48
Sec 1 Python Security Fundamentals & Secure Coding Q1 - Q12
Sec 2 Unit Testing Frameworks & Pytest Mastery Q13 - Q24
Sec 3 API Testing, Automation & Integration Q25 - Q36
Sec 4 Vulnerability Verification, CI/CD Security & 2026 Updates Q37 - Q48
Part 2 Complete Solution Key (Exemplar Responses) All 48
Part 3 Grading Rubric & Mastery Thresholds Scoring Guide
Page 2 | WGU D385 Workbook
, WGU D385 | Pytest & Security Unit Testing Workbook | 2026
PART 1: EXAMINATION QUESTIONS (48 Items)
Instructions: Select the single best answer for each question. Questions are sequenced Q1 through Q48
across four sections. Correct answers and detailed rationales are provided inline beneath each question and
summarized in Part 2.
Section 1: Python Security Fundamentals & Secure Coding
Practices (Q1-Q12)
Q1: A Python web app builds a SQL query using string concatenation: query = "SELECT * FROM users
WHERE name='" + name + "'". An attacker submits name = ' OR '1'='1. Which fix eliminates the SQL
injection vulnerability?
A. Use a parameterized query with placeholders (e.g., cursor.execute("SELECT * FROM users WHERE
name=%s", (name,))) so the database driver separates code from data. [CORRECT]
B. Escape single quotes by hand with name.replace("'", "''") and keep concatenating.
C. Wrap the input in str() before concatenating.
D. Move the query into a JavaScript string sent to the browser.
Correct Answer: A
Rationale: Parameterized queries send the SQL and the data separately, so user input can never be interpreted as SQL,
which eliminates injection. Manual escaping (B) is fragile and misses edge cases; str() (C) does not prevent injection;
moving SQL to the browser (D) exposes the query and is nonsensical.
Q2: An application must store user passwords. Which approach is the most secure in 2026?
A. Store passwords in plaintext for ease of support.
B. Hash passwords with a slow, salted KDF such as bcrypt (or Argon2) using a per-user random salt and an
appropriate work factor. [CORRECT]
C. Encrypt passwords with AES and a single shared key, storing ciphertext.
D. Hash passwords with MD5 for speed.
Correct Answer: B
Rationale: bcrypt/Argon2 are slow, salted KDFs designed to resist brute force, with per-user salts defeating rainbow
tables. Plaintext (A) and reversible encryption (C) allow password recovery by attackers; MD5 (D) is fast and unsalted,
trivially crackable.
Q3: A file-download endpoint receives a filename parameter and builds the path: path =
os.path.join(BASE_DIR, filename). An attacker submits filename = ../../../../etc/passwd. Which fix prevents
path traversal?
A. Use str.replace to remove all '..' substrings from filename.
B. Store files in a database instead of the filesystem.
C. Resolve and verify the canonical path is inside the base directory (e.g., os.path.realpath); reject if it
escapes, and never trust user input for the path. [CORRECT]
D. Concatenate the base directory and filename with a leading slash.
Correct Answer: C
Rationale: Canonicalizing the resolved path and confirming it stays within the base directory prevents traversal
because the check occurs after symlink/.. resolution. Naive string replacement of '..' (A) is bypassable (e.g., '....//'); a
database (B) is unrelated to the traversal fix; a leading slash (D) makes traversal easier, not harder.
Page 3 | WGU D385 Workbook
WGU D385
Pytest & Security Unit Testing
Workbook
48 Practice Tests
Python Security, API Testing & Vulnerability Verification | 2026
Document Type: Workbook & Practice Tests
Course: WGU D385 - Pytest & Security Unit Testing
Academic Year:
Question Count: 48 Multiple-Choice Questions
Structure: 4 Sections | 12 Questions per Section
Cognitive Mix: 30% Recall | 50% Application | 20% Analysis
Question Style: 75% Scenario-Based | 25% Direct
Includes: Complete Solution Key + Grading Rubric
Aligned with 2026/2027 academic and industry standards.
Integrates modern Python security libraries, Pytest best practices, and DevSecOps workflows.
Page 1 | WGU D385 Workbook
,WGU D385 | Pytest & Security Unit Testing Workbook | 2026
Workbook Overview
This Workbook & Practice Tests guide for WGU D385 assesses mastery across four integrated
competency domains: (1) Python Security Fundamentals and Secure Coding Practices; (2) Unit Testing
Frameworks and Pytest Mastery; (3) API Testing, Automation, and Integration; and (4) Vulnerability
Verification, CI/CD Security, and 2026 Updates. The guide mirrors the cognitive demand profile of the
course: 30 percent recall, 50 percent application, and 20 percent analysis, with 75 percent scenario-based
items and 25 percent direct items.
Each question includes the correct answer and a detailed step-by-step rationale explaining the
secure-coding pattern, Pytest feature, API-testing technique, or CI/CD security control, and explicitly
identifying why each distractor represents insecure code, a broken test, or a flawed security practice.
Distractors are engineered to reflect the most consequential errors observed in Python development and
testing.
Document Structure
Part Content Questions
Part 1 Examination Questions (48 Items) Q1 - Q48
Sec 1 Python Security Fundamentals & Secure Coding Q1 - Q12
Sec 2 Unit Testing Frameworks & Pytest Mastery Q13 - Q24
Sec 3 API Testing, Automation & Integration Q25 - Q36
Sec 4 Vulnerability Verification, CI/CD Security & 2026 Updates Q37 - Q48
Part 2 Complete Solution Key (Exemplar Responses) All 48
Part 3 Grading Rubric & Mastery Thresholds Scoring Guide
Page 2 | WGU D385 Workbook
, WGU D385 | Pytest & Security Unit Testing Workbook | 2026
PART 1: EXAMINATION QUESTIONS (48 Items)
Instructions: Select the single best answer for each question. Questions are sequenced Q1 through Q48
across four sections. Correct answers and detailed rationales are provided inline beneath each question and
summarized in Part 2.
Section 1: Python Security Fundamentals & Secure Coding
Practices (Q1-Q12)
Q1: A Python web app builds a SQL query using string concatenation: query = "SELECT * FROM users
WHERE name='" + name + "'". An attacker submits name = ' OR '1'='1. Which fix eliminates the SQL
injection vulnerability?
A. Use a parameterized query with placeholders (e.g., cursor.execute("SELECT * FROM users WHERE
name=%s", (name,))) so the database driver separates code from data. [CORRECT]
B. Escape single quotes by hand with name.replace("'", "''") and keep concatenating.
C. Wrap the input in str() before concatenating.
D. Move the query into a JavaScript string sent to the browser.
Correct Answer: A
Rationale: Parameterized queries send the SQL and the data separately, so user input can never be interpreted as SQL,
which eliminates injection. Manual escaping (B) is fragile and misses edge cases; str() (C) does not prevent injection;
moving SQL to the browser (D) exposes the query and is nonsensical.
Q2: An application must store user passwords. Which approach is the most secure in 2026?
A. Store passwords in plaintext for ease of support.
B. Hash passwords with a slow, salted KDF such as bcrypt (or Argon2) using a per-user random salt and an
appropriate work factor. [CORRECT]
C. Encrypt passwords with AES and a single shared key, storing ciphertext.
D. Hash passwords with MD5 for speed.
Correct Answer: B
Rationale: bcrypt/Argon2 are slow, salted KDFs designed to resist brute force, with per-user salts defeating rainbow
tables. Plaintext (A) and reversible encryption (C) allow password recovery by attackers; MD5 (D) is fast and unsalted,
trivially crackable.
Q3: A file-download endpoint receives a filename parameter and builds the path: path =
os.path.join(BASE_DIR, filename). An attacker submits filename = ../../../../etc/passwd. Which fix prevents
path traversal?
A. Use str.replace to remove all '..' substrings from filename.
B. Store files in a database instead of the filesystem.
C. Resolve and verify the canonical path is inside the base directory (e.g., os.path.realpath); reject if it
escapes, and never trust user input for the path. [CORRECT]
D. Concatenate the base directory and filename with a leading slash.
Correct Answer: C
Rationale: Canonicalizing the resolved path and confirming it stays within the base directory prevents traversal
because the check occurs after symlink/.. resolution. Naive string replacement of '..' (A) is bypassable (e.g., '....//'); a
database (B) is unrelated to the traversal fix; a leading slash (D) makes traversal easier, not harder.
Page 3 | WGU D385 Workbook