D487 ITAS 6231
Secure Software Design
Final Assessment (Qns & Ans)
2025
General Instructions
1. Read All Questions Carefully: Make sure you understand each question.
2. Time Management: You have a specific amount of time to complete the exam.
Keep an eye on the clock and pace yourself.
3. Allowed Materials: Only use materials that are explicitly allowed. Unauthorized
materials can lead to disqualification.
4. ANS Format: Follow the required format for your ANS. For example, multiple-
choice questions might need you to select the best ANS, while essay questions
require detailed responses.
5. Academic Integrity: Adhere to the university's honor code. Any form of cheating or
plagiarism is strictly prohibited.
6. Technical Requirements: Ensure your computer and internet connection are
stable. For online exams, you might need a webcam and microphone for proctoring
purposes.
7. Submission: Submit your ANS before the time expires. Late submissions might
not be accepted.
©2024/2025
,1. Which of the following is considered a fundamental principle
in secure software design?
- A) Accessibility
- B) Least Privilege
- C) Usability
- D) Performance
- Correct ANS: B) Least Privilege
Rationale: Least privilege minimizes the attack surface by
ensuring that users and systems have only the permissions they
need to perform their tasks.
2. What technique is often used to prevent SQL Injection
attacks?
- A) Input validation
- B) Output encoding
- C) Parameterized queries
- D) Logging
- Correct ANS: C) Parameterized queries
©2024/2025
, Rationale: Parameterized queries prevent SQL injection by
separating SQL logic from user input, thereby neutralizing
malicious inputs.
3. In the context of secure coding, what does the term "defense
in depth" refer to?
- A) Using multiple layers of security controls
- B) Only relying on firewall rules
- C) Strong encryption of all data
- D) Restricting access to sensitive information
- Correct ANS: A) Using multiple layers of security controls
Rationale: Defense in depth involves implementing a series
of defensive mechanisms to mitigate risks at various levels of the
software architecture.
4. Which of the following would be an example of a post-
deployment security measure?
- A) Code reviews
- B) Security patches and updates
- C) Threat modeling
- D) Static code analysis
- Correct ANS: B) Security patches and updates
©2024/2025
Secure Software Design
Final Assessment (Qns & Ans)
2025
General Instructions
1. Read All Questions Carefully: Make sure you understand each question.
2. Time Management: You have a specific amount of time to complete the exam.
Keep an eye on the clock and pace yourself.
3. Allowed Materials: Only use materials that are explicitly allowed. Unauthorized
materials can lead to disqualification.
4. ANS Format: Follow the required format for your ANS. For example, multiple-
choice questions might need you to select the best ANS, while essay questions
require detailed responses.
5. Academic Integrity: Adhere to the university's honor code. Any form of cheating or
plagiarism is strictly prohibited.
6. Technical Requirements: Ensure your computer and internet connection are
stable. For online exams, you might need a webcam and microphone for proctoring
purposes.
7. Submission: Submit your ANS before the time expires. Late submissions might
not be accepted.
©2024/2025
,1. Which of the following is considered a fundamental principle
in secure software design?
- A) Accessibility
- B) Least Privilege
- C) Usability
- D) Performance
- Correct ANS: B) Least Privilege
Rationale: Least privilege minimizes the attack surface by
ensuring that users and systems have only the permissions they
need to perform their tasks.
2. What technique is often used to prevent SQL Injection
attacks?
- A) Input validation
- B) Output encoding
- C) Parameterized queries
- D) Logging
- Correct ANS: C) Parameterized queries
©2024/2025
, Rationale: Parameterized queries prevent SQL injection by
separating SQL logic from user input, thereby neutralizing
malicious inputs.
3. In the context of secure coding, what does the term "defense
in depth" refer to?
- A) Using multiple layers of security controls
- B) Only relying on firewall rules
- C) Strong encryption of all data
- D) Restricting access to sensitive information
- Correct ANS: A) Using multiple layers of security controls
Rationale: Defense in depth involves implementing a series
of defensive mechanisms to mitigate risks at various levels of the
software architecture.
4. Which of the following would be an example of a post-
deployment security measure?
- A) Code reviews
- B) Security patches and updates
- C) Threat modeling
- D) Static code analysis
- Correct ANS: B) Security patches and updates
©2024/2025