WGU C706 PRACTICE EXAM FROM
ASSESSMENT
Which security design analysis is being described?
-Open design
-Complete mediation
-Economy of mechanism
-Least common mechanism - ANSWERS-Complete mediation
Which software security principle guards against the improper modification or
destruction of information and ensures the nonrepudiation and authenticity of
information?
-Integrity
-Quality
-Availability
-Confidentiality - ANSWERS-Integrity
What type of functional security requirement involves receiving, processing,
storing, transmitting, and delivering in report form?
-Logging
-Error handling
-Primary dataflow
,-Access control flow - ANSWERS-Primary dataflow
Which due diligence activity for supply chain security should occur in the initiation
phase of the software acquisition life cycle?
-Facilitating knowledge transfer between suppliers
-Lessening the risk of disseminating information during disposal
-Mitigating supply chain security risk by providing user guidance
-Developing a request for proposal (RFP) that includes supply chain security risk
management - ANSWERS--Developing a request for proposal (RFP) that includes
supply chain security risk management
Which due diligence activity for supply chain security investigates the means by
which data sets are shared and assessed?
-An on-site assessment
-A process policy review
-A third-party assessment
-A document exchange and review - ANSWERS-A document exchange and review
Consider these characteristics:
Identification of the entity making the access request
, Verification that the request has not changed since its initiation
Application of the appropriate authorization procedures
Reexamination of previously authorized requests by the same entity
Which nonfunctional security requirement provides a way to capture information
correctly and a way to store that information to help support later audits?
-Logging
-Error handling
-Primary dataflow
-Access control flow - ANSWERS-Logging
Which security concept refers to the quality of information that could cause harm
or damage if disclosed?
-Isolation
-Discretion
-Seclusion
-Sensitivity - ANSWERS-Sensitivity
Which technology would be an example of an injection flaw, according to the
OWASP Top 10?
-SQL
-API
-XML
ASSESSMENT
Which security design analysis is being described?
-Open design
-Complete mediation
-Economy of mechanism
-Least common mechanism - ANSWERS-Complete mediation
Which software security principle guards against the improper modification or
destruction of information and ensures the nonrepudiation and authenticity of
information?
-Integrity
-Quality
-Availability
-Confidentiality - ANSWERS-Integrity
What type of functional security requirement involves receiving, processing,
storing, transmitting, and delivering in report form?
-Logging
-Error handling
-Primary dataflow
,-Access control flow - ANSWERS-Primary dataflow
Which due diligence activity for supply chain security should occur in the initiation
phase of the software acquisition life cycle?
-Facilitating knowledge transfer between suppliers
-Lessening the risk of disseminating information during disposal
-Mitigating supply chain security risk by providing user guidance
-Developing a request for proposal (RFP) that includes supply chain security risk
management - ANSWERS--Developing a request for proposal (RFP) that includes
supply chain security risk management
Which due diligence activity for supply chain security investigates the means by
which data sets are shared and assessed?
-An on-site assessment
-A process policy review
-A third-party assessment
-A document exchange and review - ANSWERS-A document exchange and review
Consider these characteristics:
Identification of the entity making the access request
, Verification that the request has not changed since its initiation
Application of the appropriate authorization procedures
Reexamination of previously authorized requests by the same entity
Which nonfunctional security requirement provides a way to capture information
correctly and a way to store that information to help support later audits?
-Logging
-Error handling
-Primary dataflow
-Access control flow - ANSWERS-Logging
Which security concept refers to the quality of information that could cause harm
or damage if disclosed?
-Isolation
-Discretion
-Seclusion
-Sensitivity - ANSWERS-Sensitivity
Which technology would be an example of an injection flaw, according to the
OWASP Top 10?
-SQL
-API
-XML