Task 1 Complete Practice Guide
Static Analysis, Python Logging, Assertions, Exception Handling & Remediation | 2026 |
2027
Institution Western Governors University (WGU)
Course D385 - Software Security & Testing
Assessment Task 1 - Static Analysis, Logging & Exception Handling
Academic Year
Total Questions 40 (4 sections x 10)
Cognitive Mix 30% recall | 50% application | 20% analysis
Question Style 75% scenario-based | 25% direct
Aligned Standards OWASP Top 10 (2021), NIST SSDF, CWE, Python PEP 8/8-style security
Tooling Python, Pytest, Bandit, SonarQube, Pylint, pip-audit, logging, bcrypt/argon2
Document Type Complete Practice Guide + Exemplar + Grading Rubric
Total Points 100 (2.5 pts per question)
Scope. This guide provides a scenario-driven, hands-on practice set for the WGU D385 Task 1
performance assessment: analyzing Python code with SAST tools, implementing secure
logging and exception handling, and verifying remediations with Pytest. It integrates 2026/2027
updates including AI-assisted static analysis, ML-based log anomaly detection, and modern
secure error-handling frameworks (RFC 7807 Problem Details).
How to use. Attempt all 40 questions before consulting Part 2 (Exemplar) or Part 3 (Grading
Rubric). Each rationale explains the exact vulnerability mechanism, the secure Pythonic fix,
and why distractors represent insecure code, broken tests, or flawed error management.
WGU D385 Task 1 | 2026 | 2027
, WGU D385 Task 1 | Static Analysis, Logging, Assertions & Remediation | 2026 Complete Practice Guide
Table of Contents
Part Content Page Reference
Cover Title page and guide metadata 1
Part 1 40-Question Practice Guide (Q1-Q40) 3
Section 1: Static Analysis & Code Review (Q1-Q10) 3
Section 2: Python Logging & Security Auditing (Q11-Q20) 6
Section 3: Assertions & Exception Handling (Q21-Q30) 9
Section 4: Remediation & 2026 Updates (Q31-Q40) 12
Part 2 Complete Solution (Exemplar Answer Key) 15
Part 3 Grading Rubric & Solution Key 17
Page 2
, WGU D385 Task 1 | Static Analysis, Logging, Assertions & Remediation | 2026 Complete Practice Guide
Part 1: Complete Practice Guide (40 Questions)
Instructions: Select the single best answer (A-D) for each question. Each question is worth 2.5
points (100 points total). Mark answers on a separate sheet before verifying with Part 2 and
Part 3.
Section 1: Static Analysis, Code Review, & Vulnerability Identification
Q1: Running Bandit against a Python repository reports B105 (hardcoded password string) on
the line `API_KEY = 'sk_live_4eC39HqLyjWDarjtT1zdp7dc'`. What is the most secure
remediation?
A. Move the key to a constants.py file tracked in git
B. Store the secret in an environment variable / secrets manager and read via
os.environ, with .env ignored by git [CORRECT]
C. Base64-encode the key and decode it at runtime
D. Rename the variable to obfuscate its purpose
Correct Answer: B
Rationale: Hardcoded secrets are a Sensitive Data Exposure flaw; secrets must live in
environment variables or a vault and never in source control. Option A relocates the flaw; Option C
is reversible obfuscation; Option D does not remove the secret.
Q2: A code review finds `cursor.execute("SELECT * FROM users WHERE id=" + user_id)`.
Bandit flags B608 (hardcoded SQL expressions). Which fix is correct?
A. Wrap the query in a try/except to suppress errors
B. Use a parameterized query: cursor.execute("SELECT * FROM users WHERE id=?",
(user_id,)) [CORRECT]
C. Escape single quotes manually before concatenation
D. Switch the driver from sqlite3 to psycopg2
Correct Answer: B
Rationale: Parameterized queries separate code from data so input is never parsed as SQL,
neutralizing injection. Option A hides errors but leaves injection; Option C is an error-prone
denylist; Option D changes drivers but not the unsafe pattern.
Q3: Bandit reports B301 (pickle) on `pickle.loads(request.data)`. Why is this finding critical, and
what is the secure replacement?
A. pickle is slow; replace with marshal for speed
B. pickle.loads can execute arbitrary code on untrusted input; replace with json.loads
plus schema validation [CORRECT]
C. pickle raises too many exceptions; replace with csv
D. pickle is deprecated; replace with shelve
Correct Answer: B
Rationale: pickle deserializes arbitrary Python objects, enabling remote code execution (A08
Insecure Deserialization); JSON with schema validation is the safe alternative. Options A, C, D
mischaracterize the risk and propose unsafe or unrelated alternatives.
Page 3