Task 2 Complete Practice Guide
Vulnerability Identification & Remediation | API Security, Python Testing & Verification |
2026 | 2027
Institution Western Governors University (WGU)
Course D385 - Software Security & Testing
Assessment Task 2 - Vulnerability Identification & Remediation
Academic Year
Total Questions 40 (4 sections x 10)
Cognitive Mix 30% recall | 50% application | 20% analysis
Question Style 75% scenario-based | 25% direct
Aligned Standards OWASP Top 10 (2021), OWASP API Security Top 10 (2023), NIST SSDF
Tooling Python, Pytest, Pydantic, Bandit, OWASP ZAP, pip-audit, Sigstore
Document Type Complete Practice Guide + Exemplar + Grading Rubric
Total Points 100 (2.5 pts per question)
Scope. This guide provides a scenario-driven, hands-on practice set for the WGU D385 Task 2
performance assessment: identifying OWASP Top 10 vulnerabilities in Python code and API
responses, writing secure remediation, and constructing Pytest verification scripts. It integrates
the 2026/2027 updates including AI-assisted code remediation, software supply chain security
(Sigstore, hash-pinned dependencies), and zero-trust API architectures.
How to use. Attempt all 40 questions before consulting Part 2 (Exemplar) or Part 3 (Grading
Rubric). Each rationale explains the exact vulnerability mechanism, the secure Pythonic fix,
and why distractors represent insecure code, broken tests, or flawed security practices.
WGU D385 Task 2 | 2026 | 2027
, WGU D385 Task 2 | Vulnerability Identification & Remediation | 2026 Complete Practice Guide
Table of Contents
Part Content Page Reference
Cover Title page and guide metadata 1
Part 1 40-Question Practice Guide (Q1-Q40) 3
Section 1: Vulnerability Identification & OWASP Top 10 (Q1-Q10) 3
Section 2: API Security & Authentication Flaws (Q11-Q20) 6
Section 3: Python Remediation & Pytest Verification (Q21-Q30) 9
Section 4: DevSecOps & 2026 Updates (Q31-Q40) 12
Part 2 Complete Solution (Exemplar Answer Key) 15
Part 3 Grading Rubric & Solution Key 17
Page 2
, WGU D385 Task 2 | Vulnerability Identification & Remediation | 2026 Complete Practice Guide
Part 1: Complete Practice Guide (40 Questions)
Instructions: Select the single best answer (A-D) for each question. Each question is worth 2.5
points (100 points total). Mark answers on a separate sheet before verifying with Part 2 and
Part 3.
Section 1: Vulnerability Identification & OWASP Top 10 Analysis
Q1: A Python Flask route builds SQL as: `query = "SELECT * FROM users WHERE email='" +
email + "'"`. An attacker submits `' OR '1'='1`. Which OWASP Top 10 (2021) vulnerability is this,
and what is the secure fix?
A. Broken Access Control; fix with role checks
B. Injection (A03:2021); fix with parameterized queries / prepared statements
[CORRECT]
C. Security Misconfiguration (A05:2021); fix by patching the DB
D. Identification & Authentication Failures; fix with MFA
Correct Answer: B
Rationale: String-concatenated SQL is the canonical Injection (A03:2021) flaw; parameterized
queries separate code from data, neutralizing tautology payloads. Option A is object/function
access; Option C is config hardening, not query construction; Option D addresses login, not query
injection.
Q2: A route returns `render_template_string(user_input)` where user_input is
attacker-controlled. The attacker submits `{{ config.SECRET_KEY }}`. Which vulnerability and
remediation apply?
A. XSS; sanitize with bleach
B. Server-Side Template Injection (SSTI) under Injection (A03); use autoescaping
templates and never render untrusted input as a template [CORRECT]
C. CSRF; add a CSRF token
D. Insecure Deserialization; use JSON
Correct Answer: B
Rationale: render_template_string evaluates user input as a Jinja2 template, allowing SSTI that
can leak secrets or execute code; the fix is to pass user input as data to a pre-defined template
with autoescaping. Option A treats it as browser XSS; Option C is cross-site request forgery;
Option D is unrelated to template evaluation.
Q3: An application accepts pickle.loads(request.data) on a public endpoint. Which vulnerability
class and the secure replacement?
A. Injection; replace with regex
B. Insecure Deserialization (A08:2021); use a safe format like JSON with schema
validation [CORRECT]
C. Broken Authentication; replace pickle with hashlib
D. SSRF; block internal IPs
Correct Answer: B
Rationale: pickle.loads on untrusted data permits arbitrary code execution (A08:2021 Insecure
Deserialization); the fix is JSON (or protocol buffers) plus schema validation. Option A is the
wrong class; Option C is unrelated; Option D is outbound request forgery.
Page 3