WGU D487 (KEO1) (PKEO) PRE-ASSESSMENT
SECURE SOFTWARE DESIGN EXAM | 2025 D487
PRE-ASSESSMENT: SECURE SOFTWARE DESIGN
WITH CORRECT VERIFIED ANSWERS | ALREADY
GRADED A+ | BRAND NEW
The DREAD methodology has been used to classify an identified exploit
where: the attacker could log in as an administrator (damage potential)
the attacker could log in at any time (reproducibility) almost anybody
could perform the attack (exploitability) all system users could be
affected (affected users) any person who knows how to open dev tools
in a browser could find the vulnerability (discoverability) Which rating
should be assigned to the exploit after performing an analysis using a
ternary ranking scale where high risk = 3 points, medium risk = 2 points,
and low risk = 1 point? - ✔✔✔ Correct Answer > High risk
The software security team has been tasked with identifying who will
be involved when security vulnerabilities are reported from external
entities. They are creating a RACI matrix that will identify stakeholders
by who is responsible, accountable, consulted, and informed of any
,new vulnerabilities. Which post-release deliverable is being described?
- ✔✔✔ Correct Answer > External vulnerability disclosure response
process
What is the analysis of computer software that is performed by
executing programs on a real or virtual processor in real time?, - ✔✔✔
Correct Answer > Dynamic analysis
The scrum team is attending their morning meeting, which is scheduled
at the beginning of the work day. Each team member reports what they
accomplished yesterday, what they plan to accomplish today, and if
they have any impediments that may cause them to miss their delivery
deadline. Which scrum ceremony is the team participating in? - ✔✔✔
Correct Answer > Daily Scrum
Which person is responsible for designing, planning, and implementing
secure coding practices and security testing methodologies? - ✔✔✔
Correct Answer > Software security architect
, A company is preparing to add a new feature to its flagship software
product. The new feature is similar to features that have been added in
previous years, and the requirements are well-documented. The
project is expected to last three to four months, at which time the new
feature will be released to customers. Project team members will focus
solely on the new feature until the project ends. Which software
development methodology is being used? - ✔✔✔ Correct Answer >
Waterfall
A new product will require an administration section for a small
number of users. Normal users will be able to view limited customer
information and should not see admin functionality within the
application. Which concept is being used? - ✔✔✔ Correct Answer >
Principle of least privilege
What is a list of information security vulnerabilities that aims to provide
names for publicly known problems? - ✔✔✔ Correct Answer >
Common computer vulnerabilities and exposures (CVE)
SECURE SOFTWARE DESIGN EXAM | 2025 D487
PRE-ASSESSMENT: SECURE SOFTWARE DESIGN
WITH CORRECT VERIFIED ANSWERS | ALREADY
GRADED A+ | BRAND NEW
The DREAD methodology has been used to classify an identified exploit
where: the attacker could log in as an administrator (damage potential)
the attacker could log in at any time (reproducibility) almost anybody
could perform the attack (exploitability) all system users could be
affected (affected users) any person who knows how to open dev tools
in a browser could find the vulnerability (discoverability) Which rating
should be assigned to the exploit after performing an analysis using a
ternary ranking scale where high risk = 3 points, medium risk = 2 points,
and low risk = 1 point? - ✔✔✔ Correct Answer > High risk
The software security team has been tasked with identifying who will
be involved when security vulnerabilities are reported from external
entities. They are creating a RACI matrix that will identify stakeholders
by who is responsible, accountable, consulted, and informed of any
,new vulnerabilities. Which post-release deliverable is being described?
- ✔✔✔ Correct Answer > External vulnerability disclosure response
process
What is the analysis of computer software that is performed by
executing programs on a real or virtual processor in real time?, - ✔✔✔
Correct Answer > Dynamic analysis
The scrum team is attending their morning meeting, which is scheduled
at the beginning of the work day. Each team member reports what they
accomplished yesterday, what they plan to accomplish today, and if
they have any impediments that may cause them to miss their delivery
deadline. Which scrum ceremony is the team participating in? - ✔✔✔
Correct Answer > Daily Scrum
Which person is responsible for designing, planning, and implementing
secure coding practices and security testing methodologies? - ✔✔✔
Correct Answer > Software security architect
, A company is preparing to add a new feature to its flagship software
product. The new feature is similar to features that have been added in
previous years, and the requirements are well-documented. The
project is expected to last three to four months, at which time the new
feature will be released to customers. Project team members will focus
solely on the new feature until the project ends. Which software
development methodology is being used? - ✔✔✔ Correct Answer >
Waterfall
A new product will require an administration section for a small
number of users. Normal users will be able to view limited customer
information and should not see admin functionality within the
application. Which concept is being used? - ✔✔✔ Correct Answer >
Principle of least privilege
What is a list of information security vulnerabilities that aims to provide
names for publicly known problems? - ✔✔✔ Correct Answer >
Common computer vulnerabilities and exposures (CVE)