WGU - D487 Exam
Practice Questions
and Correct Detailed
Answers Latest
Update This Year
How is BSIMM primarily used?
BSIMM measures maturity over time by
tracking and comparing an
organization's security maturity
across different domains based on
real-world data from multiple
companies. It provides a
benchmarking approach that helps
organizations determine where they
stand relative to industry peers and
track improvement over time
1
,SSDL BSIMM
SSDL Touchpoints in BSIMM focuses
on activities directly related to the
software security development
lifecycle (SSDL), including security
testing, code review, and architecture
analysis.
The software security group is
conducting a maturity assessment
using the Building Security in Maturity
Model (BSIMM). They are currently
focused on reviewing security testing
results from recently completed
initiatives. Which BSIMM domain is
being assessed?
Software security development life
cycle (SSDL) touchpoints
In an Agile SDL, which type of
requirement includes Remote
Procedure Call (RPC) fuzz testing?
Bucket Requirement
2
,Explanation:
Bucket requirements are security
activities that do not need to be
performed every sprint but should be
addressed within a set timeframe (e.g.,
every quarter, release cycle, or
milestone).
RPC fuzz testing is a security testing
activity that can be scheduled
periodically, making it a bucket
requirement rather than an every-
sprint requirement.
Unlike one-time requirements, which
are implemented once and do not
repeat, bucket requirements recur on
a structured schedule.
Which secure coding best practice
includes using parameterized queries,
encrypted connection strings, and
strong authentication?
Database Security
3
, Which secure coding best practice
says that all information passed to
other systems should be encrypted?
Communication Security
Explanation:
Encryption in transit protects data
from eavesdropping and man-in-the-
middle (MITM) attacks.
Secure communication
protocols like TLS (Transport Layer
Security) and HTTPS ensure
confidentiality and integrity.
End-to-end encryption prevents
unauthorized access during data
exchange between systems.
A software security team member has
created data flow diagrams, chosen
the STRIDE methodology to perform
threat reviews, and created the
security assessment for a new
4
Practice Questions
and Correct Detailed
Answers Latest
Update This Year
How is BSIMM primarily used?
BSIMM measures maturity over time by
tracking and comparing an
organization's security maturity
across different domains based on
real-world data from multiple
companies. It provides a
benchmarking approach that helps
organizations determine where they
stand relative to industry peers and
track improvement over time
1
,SSDL BSIMM
SSDL Touchpoints in BSIMM focuses
on activities directly related to the
software security development
lifecycle (SSDL), including security
testing, code review, and architecture
analysis.
The software security group is
conducting a maturity assessment
using the Building Security in Maturity
Model (BSIMM). They are currently
focused on reviewing security testing
results from recently completed
initiatives. Which BSIMM domain is
being assessed?
Software security development life
cycle (SSDL) touchpoints
In an Agile SDL, which type of
requirement includes Remote
Procedure Call (RPC) fuzz testing?
Bucket Requirement
2
,Explanation:
Bucket requirements are security
activities that do not need to be
performed every sprint but should be
addressed within a set timeframe (e.g.,
every quarter, release cycle, or
milestone).
RPC fuzz testing is a security testing
activity that can be scheduled
periodically, making it a bucket
requirement rather than an every-
sprint requirement.
Unlike one-time requirements, which
are implemented once and do not
repeat, bucket requirements recur on
a structured schedule.
Which secure coding best practice
includes using parameterized queries,
encrypted connection strings, and
strong authentication?
Database Security
3
, Which secure coding best practice
says that all information passed to
other systems should be encrypted?
Communication Security
Explanation:
Encryption in transit protects data
from eavesdropping and man-in-the-
middle (MITM) attacks.
Secure communication
protocols like TLS (Transport Layer
Security) and HTTPS ensure
confidentiality and integrity.
End-to-end encryption prevents
unauthorized access during data
exchange between systems.
A software security team member has
created data flow diagrams, chosen
the STRIDE methodology to perform
threat reviews, and created the
security assessment for a new
4