WGU D487 | Questions with 100% Verified Answers | Latest
Update 2026/2027
Question: Product Owner
Answer: Defines WHAT the business needs
Question: Security Architect
Answer: Determines HOW security is designed into the system
Question: Developer
Answer: Implements the design
Question: QA Tester
Answer: Verifies the implementation
Question: What is the role of a Security Architect?
Answer: is responsible for designing how security is built into the application and ensuring the
architecture meets the organization's security requirements.
Question: Scrum Master
Answer: How does the team work effectively
Question: Project manager
Answer: is in charge of the project
Question: Security Architect
Answer: Owns the security design
Question: Product Owner
Answer: Owns the product requirements and priorities
Question: Developer
Answer: owns the implementation
Question: Tester
Answer: Own verification
Question: Architects
Answer: Design (Blueprint)
Question: Developers
Answer: Build (Hammer)
,Question: Security Champion
Answer: Security advocate on development team
Question: Data Minimization
Answer: Collects only the information you actually need
Question: Anonymization
Answer: Identity cannot reasonably be recovered.
Question: Pseudonymized
Answer: Identity replaced with another identifier.
Question: Functional Requirements
Answer: Requirements that describe what the system will do and its core purpose
Question: Non-Functional Requirements
Answer: Requirements that describe constraints or restrictions without changing the system's
core
purpose
Question: Privacy Impact Assessment (PIA)
Answer: A Process that evaluates impact of handling Personally Identifiable Information (PII)
Question: Product Risk Profile
Answer: Helps determine the products overall risk from different perspectives
Question: Requirements Traceability Matrix (RTM)
Answer: A table that maps security requirements throughout the project
Question: Security Assessment (A1)
Answer: the first phase of the security development life cycle
Question: Identifies product risks
Defines Security Milestones
Creates the security roadmap
Answer: Security Assessment (A1)
Question: Threat Profile
Answer: Describes the environment where the software will operate and the threats it may
face.
Question: Waterfall
Answer: Fixed phases,
, Question: Alpha Testing
Answer: Testing done by the developers themselves
Question: Beta level testing
Answer: Testing done by those not familiar with the actual development of the system
Question: Agile
Answer: Focuses on: Flexibility Quick improvements frequent customer feedback small
releases
instead of one giant release.
Question: Black box testing
Answer: tests from an external perspective with no prior knowledge of the software
Question: (A3 Phase)
Answer: Design and Development
Question: Design and Development (A3) Phase:
Answer: the third phase of the security development life cycle, in which you analyze and test
software to determine security and privacy issues as you make informed decisions
moving forward with your software
Question: External Resources
Answer: resources hired on a temporary basis to come into a project, test the application, and
report findings
Question: Functional testing scripts
Answer: step-by-step instructions for a specific scenario or situation
Question: Gray box
Answer: analyzes the source code for the software to help design the test cases.
Question: Internal Resources
Answer: resources from the company's organization
Question: Secure Testing Scripts
Answer: Scripts created specifically for the application being tested
Question: System test
Answer: test the system and its interaction with other systems
Question: White box testing
Answer: tests from an internal perspective with full knowledge of the software
Update 2026/2027
Question: Product Owner
Answer: Defines WHAT the business needs
Question: Security Architect
Answer: Determines HOW security is designed into the system
Question: Developer
Answer: Implements the design
Question: QA Tester
Answer: Verifies the implementation
Question: What is the role of a Security Architect?
Answer: is responsible for designing how security is built into the application and ensuring the
architecture meets the organization's security requirements.
Question: Scrum Master
Answer: How does the team work effectively
Question: Project manager
Answer: is in charge of the project
Question: Security Architect
Answer: Owns the security design
Question: Product Owner
Answer: Owns the product requirements and priorities
Question: Developer
Answer: owns the implementation
Question: Tester
Answer: Own verification
Question: Architects
Answer: Design (Blueprint)
Question: Developers
Answer: Build (Hammer)
,Question: Security Champion
Answer: Security advocate on development team
Question: Data Minimization
Answer: Collects only the information you actually need
Question: Anonymization
Answer: Identity cannot reasonably be recovered.
Question: Pseudonymized
Answer: Identity replaced with another identifier.
Question: Functional Requirements
Answer: Requirements that describe what the system will do and its core purpose
Question: Non-Functional Requirements
Answer: Requirements that describe constraints or restrictions without changing the system's
core
purpose
Question: Privacy Impact Assessment (PIA)
Answer: A Process that evaluates impact of handling Personally Identifiable Information (PII)
Question: Product Risk Profile
Answer: Helps determine the products overall risk from different perspectives
Question: Requirements Traceability Matrix (RTM)
Answer: A table that maps security requirements throughout the project
Question: Security Assessment (A1)
Answer: the first phase of the security development life cycle
Question: Identifies product risks
Defines Security Milestones
Creates the security roadmap
Answer: Security Assessment (A1)
Question: Threat Profile
Answer: Describes the environment where the software will operate and the threats it may
face.
Question: Waterfall
Answer: Fixed phases,
, Question: Alpha Testing
Answer: Testing done by the developers themselves
Question: Beta level testing
Answer: Testing done by those not familiar with the actual development of the system
Question: Agile
Answer: Focuses on: Flexibility Quick improvements frequent customer feedback small
releases
instead of one giant release.
Question: Black box testing
Answer: tests from an external perspective with no prior knowledge of the software
Question: (A3 Phase)
Answer: Design and Development
Question: Design and Development (A3) Phase:
Answer: the third phase of the security development life cycle, in which you analyze and test
software to determine security and privacy issues as you make informed decisions
moving forward with your software
Question: External Resources
Answer: resources hired on a temporary basis to come into a project, test the application, and
report findings
Question: Functional testing scripts
Answer: step-by-step instructions for a specific scenario or situation
Question: Gray box
Answer: analyzes the source code for the software to help design the test cases.
Question: Internal Resources
Answer: resources from the company's organization
Question: Secure Testing Scripts
Answer: Scripts created specifically for the application being tested
Question: System test
Answer: test the system and its interaction with other systems
Question: White box testing
Answer: tests from an internal perspective with full knowledge of the software