WGU D487 Oa 2025 Test Bank 3 With 420
Questions And Correct Answers (100% Correct
Verified Answers) D487 Secure Software Design
Objective Assessment 2025 Test Bank V3
What do DevOps teams primarily focus on?
a. Ensuring compliance with BSIMM metrics
b. Collaboration for ongoing operations, enhancements, defect removal, and
optimization of resources
c. Automating the deployment of applications in cloud environments
d. Streamlining legacy code to improve security
b. Collaboration for ongoing operations, enhancements, defect removal, and
optimization of resources
How has cloud technology influenced software development?
a. By replacing legacy systems entirely
b. By enabling new approaches to building, deploying, and using applications
c. By eliminating security risks in deployment environments
d. By requiring the exclusive use of Agile methodologies
b. By enabling new approaches to building, deploying, and using applications
Your company is transitioning to a public cloud service. What is a significant
security challenge introduced by this move?
a. Increased development cycle times
b. Enhanced compliance with deployment standards
c. New risks associated with shared infrastructure and misconfigurations
d. Limited adoption of DevOps practices
c. New risks associated with shared infrastructure and misconfigurations
What are the four business functions defined in OpenSAMM?
pg. 1
,a. Governance, construction, verification, and deployment
b. Planning, execution, reporting, and testing
c. Threat assessment, architecture, testing, and delivery
d. Agile, Cloud, DevOps, and Digital Enterprise
a. Governance, construction, verification, and deployment
A DevOps team is tasked with optimizing software performance while addressing
defects and implementing enhancements. What is their primary objective?
a. Reducing the cost of cloud operations
b. Balancing ongoing operations with continuous delivery and improvement
c. Conducting penetration testing for new releases
d. Automating code deployment to minimize human interaction
b. Balancing ongoing operations with continuous delivery and improvement
How has cloud technology impacted software development and deployment?
a. It has eliminated the need for traditional SDL processes.
b. It has increased the complexity of compliance regulations.
c. It has required a rethinking of how applications are built, deployed, and used.
d. It has removed the need for deployment-specific practices.
c. It has required a rethinking of how applications are built, deployed, and used.
What is a digital enterprise?
a. A company that develops only cloud-native applications
b. An organization using technology to enable and improve business activities
c. A methodology for agile development
d. A framework for implementing DevOps practices
b. An organization using technology to enable and improve business activities
What is BSIMM, and how is it used?
a. A tool for automating the vulnerability scanning process
b. A study of existing software security initiatives for gathering data on security
practices
pg. 2
,c. A framework for transitioning legacy applications to cloud environments
d. A set of standards for compliance testing
b. A study of existing software security initiatives for gathering data on security
practices
Which of the following is an example of a vulnerability that security testing aims
to identify?
a. Inefficient database queries
b. Input validation flaws like SQL injection
c. Poor user interface design
d. Lack of mobile app compatibility
b. Input validation flaws like SQL injection
What is the primary purpose of dynamic analysis?
a. To identify vulnerabilities by executing the software in a runtime environment
b. To validate software against corporate security policies
c. To detect issues in the source code before deployment
d. To optimize the software's performance metrics
a. To identify vulnerabilities by executing the software in a runtime environment
What is a key advantage of dynamic analysis compared to static analysis?
a. It requires no runtime environment.
b. It identifies runtime vulnerabilities that static analysis cannot.
c. It guarantees 100% detection of vulnerabilities.
d. It eliminates the need for manual code reviews.
b. It identifies runtime vulnerabilities that static analysis cannot.
What is a limitation of dynamic analysis?
a. It requires source or binary code access.
b. It cannot trace issues back to specific lines of code.
c. It is less effective at detecting runtime vulnerabilities.
d. It is only suitable for white box testing.
b. It cannot trace issues back to specific lines of code.
pg. 3
, Which of the following is NOT typically included in threat modeling artifacts?
A) High-level executive threat modeling reports
B) Detailed system architectural designs
C) Data flow diagrams
D) Metrics for evaluating success
D) Metrics for evaluating success
Why is early stakeholder engagement important in Phase A3?
A) To confirm deliverables align with future testing and compliance needs.
B) To reduce the scope of development activities.
C) To eliminate non-security related deliverables.
D) To prioritize operational efficiency over compliance.
A) To confirm deliverables align with future testing and compliance needs.
Which artifact focuses on breaking down an application to identify its key
functions and data flows?
A) Threat modeling artifacts
B) Policy compliance analysis
C) Application decomposition
D) Security metrics documentation
C) Application decomposition
What is the primary objective of documented metrics in Phase A3 deliverables?
A) To establish baselines for ongoing security assessments.
B) To determine project profitability.
C) To analyze system user experience.
D) To reduce the number of identified vulnerabilities.
A) To establish baselines for ongoing security assessments.
What is a key reason for introducing security early in the SDL?
A) It reduces overall project costs.
B) It guarantees compliance with legal standards.
pg. 4
Questions And Correct Answers (100% Correct
Verified Answers) D487 Secure Software Design
Objective Assessment 2025 Test Bank V3
What do DevOps teams primarily focus on?
a. Ensuring compliance with BSIMM metrics
b. Collaboration for ongoing operations, enhancements, defect removal, and
optimization of resources
c. Automating the deployment of applications in cloud environments
d. Streamlining legacy code to improve security
b. Collaboration for ongoing operations, enhancements, defect removal, and
optimization of resources
How has cloud technology influenced software development?
a. By replacing legacy systems entirely
b. By enabling new approaches to building, deploying, and using applications
c. By eliminating security risks in deployment environments
d. By requiring the exclusive use of Agile methodologies
b. By enabling new approaches to building, deploying, and using applications
Your company is transitioning to a public cloud service. What is a significant
security challenge introduced by this move?
a. Increased development cycle times
b. Enhanced compliance with deployment standards
c. New risks associated with shared infrastructure and misconfigurations
d. Limited adoption of DevOps practices
c. New risks associated with shared infrastructure and misconfigurations
What are the four business functions defined in OpenSAMM?
pg. 1
,a. Governance, construction, verification, and deployment
b. Planning, execution, reporting, and testing
c. Threat assessment, architecture, testing, and delivery
d. Agile, Cloud, DevOps, and Digital Enterprise
a. Governance, construction, verification, and deployment
A DevOps team is tasked with optimizing software performance while addressing
defects and implementing enhancements. What is their primary objective?
a. Reducing the cost of cloud operations
b. Balancing ongoing operations with continuous delivery and improvement
c. Conducting penetration testing for new releases
d. Automating code deployment to minimize human interaction
b. Balancing ongoing operations with continuous delivery and improvement
How has cloud technology impacted software development and deployment?
a. It has eliminated the need for traditional SDL processes.
b. It has increased the complexity of compliance regulations.
c. It has required a rethinking of how applications are built, deployed, and used.
d. It has removed the need for deployment-specific practices.
c. It has required a rethinking of how applications are built, deployed, and used.
What is a digital enterprise?
a. A company that develops only cloud-native applications
b. An organization using technology to enable and improve business activities
c. A methodology for agile development
d. A framework for implementing DevOps practices
b. An organization using technology to enable and improve business activities
What is BSIMM, and how is it used?
a. A tool for automating the vulnerability scanning process
b. A study of existing software security initiatives for gathering data on security
practices
pg. 2
,c. A framework for transitioning legacy applications to cloud environments
d. A set of standards for compliance testing
b. A study of existing software security initiatives for gathering data on security
practices
Which of the following is an example of a vulnerability that security testing aims
to identify?
a. Inefficient database queries
b. Input validation flaws like SQL injection
c. Poor user interface design
d. Lack of mobile app compatibility
b. Input validation flaws like SQL injection
What is the primary purpose of dynamic analysis?
a. To identify vulnerabilities by executing the software in a runtime environment
b. To validate software against corporate security policies
c. To detect issues in the source code before deployment
d. To optimize the software's performance metrics
a. To identify vulnerabilities by executing the software in a runtime environment
What is a key advantage of dynamic analysis compared to static analysis?
a. It requires no runtime environment.
b. It identifies runtime vulnerabilities that static analysis cannot.
c. It guarantees 100% detection of vulnerabilities.
d. It eliminates the need for manual code reviews.
b. It identifies runtime vulnerabilities that static analysis cannot.
What is a limitation of dynamic analysis?
a. It requires source or binary code access.
b. It cannot trace issues back to specific lines of code.
c. It is less effective at detecting runtime vulnerabilities.
d. It is only suitable for white box testing.
b. It cannot trace issues back to specific lines of code.
pg. 3
, Which of the following is NOT typically included in threat modeling artifacts?
A) High-level executive threat modeling reports
B) Detailed system architectural designs
C) Data flow diagrams
D) Metrics for evaluating success
D) Metrics for evaluating success
Why is early stakeholder engagement important in Phase A3?
A) To confirm deliverables align with future testing and compliance needs.
B) To reduce the scope of development activities.
C) To eliminate non-security related deliverables.
D) To prioritize operational efficiency over compliance.
A) To confirm deliverables align with future testing and compliance needs.
Which artifact focuses on breaking down an application to identify its key
functions and data flows?
A) Threat modeling artifacts
B) Policy compliance analysis
C) Application decomposition
D) Security metrics documentation
C) Application decomposition
What is the primary objective of documented metrics in Phase A3 deliverables?
A) To establish baselines for ongoing security assessments.
B) To determine project profitability.
C) To analyze system user experience.
D) To reduce the number of identified vulnerabilities.
A) To establish baselines for ongoing security assessments.
What is a key reason for introducing security early in the SDL?
A) It reduces overall project costs.
B) It guarantees compliance with legal standards.
pg. 4