• Wrong document? Swap it for free
  • Written by students who passed
  • Immediately available after payment
  • Read online or as PDF
Sell
Where do you study
Your language
Document preview thumbnail
Preview 2 out of 14 pages
Exam (elaborations)

WGU C706 Secure Software Design Study Guide Questions and Answers (2024/2025) (Verified Answers)

Document preview thumbnail
Preview 2 out of 14 pages

WGU C706 Secure Software Design Study Guide Questions and Answers (2024/2025) (Verified Answers) Confidentiality - -In information security, confidentiality "is the property, that information is not made available or disclosed to unauthorized individuals, entities, or processes" Integrity - -In information security, data integrity means maintaining and assuring the accuracy and completeness of data over its entire life-cycle. This means that data cannot be modified in an unauthorized or undetected manner. This can be also used to validate databases to make sure none of the data is corrupt or modified in an unauthorized matter. Availability - -For any information system to serve its purpose, the information must be available when it is needed. This means that the computing systems used to store and process the information, the security controls used to protect it, and the communication channels used to access it must be functioning correctly. Secure Software Design Features - -Confidentiality: Public Key Infrastructure (PKI) and Cryptography/Encryption Availability: Offsite back-up and Redundancy Integrity: Hashing, Message Digest (MD5), non repudiation and digital signatures Software Software Architect - -The software architect moves analysis to implementation and analyzes the requirements and use cases as activities to perform as part of the development process. That person can also develop class diagrams. Security Practitioner Roles - -Release Manager: Deployment Architect: Design Developer: Coding Business Analyst/Project Manager: Requir

Content preview

WGU C706 Secure Software Design Study Guide
Questions and Answers (2024/2025) (Verified Answers)
Confidentiality - -In information security, confidentiality "is the property, that
information is not made available or
disclosed to unauthorized individuals, entities, or processes"

Integrity - -In information security, data integrity means maintaining and assuring the
accuracy and completeness of data over its entire life-cycle. This means that data cannot
be modified in an unauthorized or undetected manner. This can be also used to validate
databases to make sure none of the data is corrupt or modified in an unauthorized matter.

Availability - -For any information system to serve its purpose, the information must
be available when it is needed. This means that the computing systems used to store and
process the information, the security controls used to protect it, and the communication
channels used to access it must be functioning correctly.

Secure Software Design Features - -Confidentiality: Public Key Infrastructure (PKI)
and Cryptography/Encryption
Availability: Offsite back-up and Redundancy
Integrity: Hashing, Message Digest (MD5), non repudiation and digital signatures
Software

Software Architect - -The software architect moves analysis to implementation and
analyzes the requirements and use cases as activities to perform as part of the
development process. That person can also develop class diagrams.

Security Practitioner Roles - -Release Manager: Deployment
Architect: Design
Developer: Coding
Business Analyst/Project Manager: Requirements Gathering

Red Team - -These are teams of people familiar with the infrastructure of the
company and the languages of the software being developed. Their mission is to kill the
system as the developers build it.

Static Analysis - -Static analysis, also called static code analysis, is a method of
computer program debugging that is done by examining the code without executing the
program. The process provides an understanding of the code structure, and can help to
ensure that the code adheres to industry standards. It's also referred as code review.

MD5 Hash - -The MD5 algorithm is a widely used hash function producing a 128-bit
hash value. Although MD5 was initially designed to be used as a cryptographic hash

, WGU C706 Secure Software Design Study Guide
Questions and Answers (2024/2025) (Verified Answers)
function, it has been found to suffer from extensive vulnerabilities. It can still be used as a
checksum to verify data integrity, but only against unintentional corruption. (Integrity)

SHA-256 - -The SHA (Secure Hash Algorithm) is one of a number of cryptographic
hash functions. A cryptographic hash is like a signature for a text or a data file. SHA-256
algorithm generates an almost-unique, fixed size 256-bit (32-byte) hash. Hash is a one way
function - it cannot be decrypted back. (Integrity)

Advanced Encryption Standard (AES) - -AES (acronym of Advanced Encryption
Standard) is a symmetric encryption algorithm. The algorithm was developed by two
Belgian cryptographer Joan Daemen and Vincent Rijmen. AES was
designed to be efficient in both hardware and software, and supports a block length of 128
bits and key lengths of 128, 192, and 256 bits. (Confidentiality)

Stochastic - -The analogy between safety and security is particularly close. The main
difference is that safety-relevant faults are stochastic (i.e., unintentional or accidental),
whereas security-relevant faults are "sponsored," i.e., intentionally created and activated
through conscious and intentional human agency.

Fuzz Testing - -Is used to see if the system has solid exception handling to the input it
receives. Is the use of malformed or random input into a system in order to intentionally
produce failure. This is a very easy process of feeding garbage to the system when it
expects a formatted input, and it is always a good idea to feed as much garbage as possible
to an input field

Three (3) Tier - -The 3 tier architecture model removes the business logic from the
client end of the system. It generally places the business logic on a separate server from
the client. The data access portion of the system resides on a 3rd tier, which is separate
from both the client and the business logic platform

T-MAP - -USC's Thread Modeling based on Attacking Path Analysis (T-MAP) is a risk
management approac that quantifies severity weights of relevant attacking paths for COTS-
based systems. T-MAP's strengths lie in its ability to maintain sensitivity to an organization's
business value priorities and Information Technology (IT) environment, to prioritize and
estimate security investment effectiveness and evaluate performance, and to
communicate executive-friendly vulnerability details as threat profiles to help evaluate
cost efficiency.

Trike - -Trike is an open source conceptual framework, methodology, and toolset
designed to autogenerate repeatable threat models. Its methodology enables the risk
analyst to accurately and completely describe the security characteristics of the system,

Document information

Uploaded on
October 27, 2024
Number of pages
14
Written in
2024/2025
Type
Exam (elaborations)
Contains
Questions & answers
$10.49

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
learndirect
3.8
(8)
Sold
56
Followers
10
Items
3655
Last sold
2 months ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions