Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 110 pages
Exam (elaborations)

WGU D487 Oa 2025 Test Bank 3 With 420 Questions And Correct Answers (100% Correct Verified Answers) D487 Secure Software Design Objective Assessment 2025 Test Bank V3

Document preview thumbnail
Preview 4 out of 110 pages

WGU D487 Oa 2025 Test Bank 3 With 420 Questions And Correct Answers (100% Correct Verified Answers) D487 Secure Software Design Objective Assessment 2025 Test Bank V3

Content preview

WGU D487 Oa 2025 Test Bank 3 With 420
Questions And Correct Answers (100% Correct
Verified Answers) D487 Secure Software Design
Objective Assessment 2025 Test Bank V3

What do DevOps teams primarily focus on?

a. Ensuring compliance with BSIMM metrics
b. Collaboration for ongoing operations, enhancements, defect removal, and
optimization of resources
c. Automating the deployment of applications in cloud environments
d. Streamlining legacy code to improve security
b. Collaboration for ongoing operations, enhancements, defect removal, and
optimization of resources
How has cloud technology influenced software development?

a. By replacing legacy systems entirely
b. By enabling new approaches to building, deploying, and using applications
c. By eliminating security risks in deployment environments
d. By requiring the exclusive use of Agile methodologies
b. By enabling new approaches to building, deploying, and using applications
Your company is transitioning to a public cloud service. What is a significant
security challenge introduced by this move?

a. Increased development cycle times
b. Enhanced compliance with deployment standards
c. New risks associated with shared infrastructure and misconfigurations
d. Limited adoption of DevOps practices
c. New risks associated with shared infrastructure and misconfigurations
What are the four business functions defined in OpenSAMM?



pg. 1

,a. Governance, construction, verification, and deployment
b. Planning, execution, reporting, and testing
c. Threat assessment, architecture, testing, and delivery
d. Agile, Cloud, DevOps, and Digital Enterprise
a. Governance, construction, verification, and deployment
A DevOps team is tasked with optimizing software performance while addressing
defects and implementing enhancements. What is their primary objective?

a. Reducing the cost of cloud operations
b. Balancing ongoing operations with continuous delivery and improvement
c. Conducting penetration testing for new releases
d. Automating code deployment to minimize human interaction
b. Balancing ongoing operations with continuous delivery and improvement
How has cloud technology impacted software development and deployment?

a. It has eliminated the need for traditional SDL processes.
b. It has increased the complexity of compliance regulations.
c. It has required a rethinking of how applications are built, deployed, and used.
d. It has removed the need for deployment-specific practices.
c. It has required a rethinking of how applications are built, deployed, and used.
What is a digital enterprise?

a. A company that develops only cloud-native applications
b. An organization using technology to enable and improve business activities
c. A methodology for agile development
d. A framework for implementing DevOps practices
b. An organization using technology to enable and improve business activities
What is BSIMM, and how is it used?

a. A tool for automating the vulnerability scanning process
b. A study of existing software security initiatives for gathering data on security
practices



pg. 2

,c. A framework for transitioning legacy applications to cloud environments
d. A set of standards for compliance testing
b. A study of existing software security initiatives for gathering data on security
practices
Which of the following is an example of a vulnerability that security testing aims
to identify?

a. Inefficient database queries
b. Input validation flaws like SQL injection
c. Poor user interface design
d. Lack of mobile app compatibility
b. Input validation flaws like SQL injection
What is the primary purpose of dynamic analysis?

a. To identify vulnerabilities by executing the software in a runtime environment
b. To validate software against corporate security policies
c. To detect issues in the source code before deployment
d. To optimize the software's performance metrics
a. To identify vulnerabilities by executing the software in a runtime environment
What is a key advantage of dynamic analysis compared to static analysis?

a. It requires no runtime environment.
b. It identifies runtime vulnerabilities that static analysis cannot.
c. It guarantees 100% detection of vulnerabilities.
d. It eliminates the need for manual code reviews.
b. It identifies runtime vulnerabilities that static analysis cannot.
What is a limitation of dynamic analysis?

a. It requires source or binary code access.
b. It cannot trace issues back to specific lines of code.
c. It is less effective at detecting runtime vulnerabilities.
d. It is only suitable for white box testing.
b. It cannot trace issues back to specific lines of code.

pg. 3

, Which of the following is NOT typically included in threat modeling artifacts?

A) High-level executive threat modeling reports
B) Detailed system architectural designs
C) Data flow diagrams
D) Metrics for evaluating success
D) Metrics for evaluating success
Why is early stakeholder engagement important in Phase A3?

A) To confirm deliverables align with future testing and compliance needs.
B) To reduce the scope of development activities.
C) To eliminate non-security related deliverables.
D) To prioritize operational efficiency over compliance.
A) To confirm deliverables align with future testing and compliance needs.
Which artifact focuses on breaking down an application to identify its key
functions and data flows?

A) Threat modeling artifacts
B) Policy compliance analysis
C) Application decomposition
D) Security metrics documentation
C) Application decomposition
What is the primary objective of documented metrics in Phase A3 deliverables?

A) To establish baselines for ongoing security assessments.
B) To determine project profitability.
C) To analyze system user experience.
D) To reduce the number of identified vulnerabilities.
A) To establish baselines for ongoing security assessments.
What is a key reason for introducing security early in the SDL?

A) It reduces overall project costs.
B) It guarantees compliance with legal standards.


pg. 4

Document information

Uploaded on
January 17, 2025
Number of pages
110
Written in
2024/2025
Type
Exam (elaborations)
Contains
Questions & answers
$30.49
Purchased by 13 students

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
muriithikelvin
3.9
(308)
Sold
1586
Followers
581
Items
3677
Last sold
1 hour ago


Reviews from verified buyers




Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions