WGU-C706 Secure Software Design (Pre-Assessment)
Study online at https://quizlet.com/_9pp8vc
1. Which due diligence activity for supply chain security Developing a request for
should occur in the initiation phase of the software proposal (RFP) that in-
acquisition life cycle? cludes supply chain secu-
rity risk management
2. Which due diligence activity for supply chain security A document exchange and
investigates the means by which data sets are shared review
and assessed?
3. Identification of the entity making the access request Complete mediation
Verification that the request has not changed since its
initiation
Application of the appropriate authorization proce-
dures
Reexamination of previously authorized requests by
the same entity
Which security design analysis is being described?
4. Which software security principle guards against the Integrity
improper modification or destruction of information
and ensures the nonrepudiation and authenticity of
information?
5. What type of functional security requirement involves Primary dataflow
receiving, processing, storing, transmitting, and deliv-
ering in report form?
6. Which nonfunctional security requirement provides a Logging
way to capture information correctly and a way to store
that information to help support later audits?
7. Which security concept refers to the quality of informa- Sensitivity
tion that could cause harm or damage if disclosed?
, WGU-C706 Secure Software Design (Pre-Assessment)
Study online at https://quizlet.com/_9pp8vc
8. Which technology would be an example of an injection SQL
flaw, according to the OWASP Top 10?
9. A company is creating a new software to track cus- Create multiple layers of
tomer balance and wants to design a secure applica- protection so that a sub-
tion. sequent layer provides
protection if a layer is
Which best practice should be applied? breached
10. A company is developing a secure software that has to Open design
be evaluated and tested by a large number of experts.
Which security principle should be applied?
11. Which type of TCP scanning indicates that a system TCP SYN scanning
is moving to the second phase in a three-way TCP
handshake?
12. Which evaluation technique provides invalid, unex- Fuzz testing
pected, or random data to the inputs of a computer
software program?
13. Which approach provides an opportunity to improve Software assurance matu-
the software development life cycle by tailoring the rity model (SAMM)
process to the specific risks facing the organization?
14. Which phase contains sophisticated software develop- Optimizing
ment processes that ensure that feedback from one
phase reaches to the previous phase to improve future
results?
15. The activities for compliance include ensuring collect- PIA
ed information is only used for intended purposes,
Study online at https://quizlet.com/_9pp8vc
1. Which due diligence activity for supply chain security Developing a request for
should occur in the initiation phase of the software proposal (RFP) that in-
acquisition life cycle? cludes supply chain secu-
rity risk management
2. Which due diligence activity for supply chain security A document exchange and
investigates the means by which data sets are shared review
and assessed?
3. Identification of the entity making the access request Complete mediation
Verification that the request has not changed since its
initiation
Application of the appropriate authorization proce-
dures
Reexamination of previously authorized requests by
the same entity
Which security design analysis is being described?
4. Which software security principle guards against the Integrity
improper modification or destruction of information
and ensures the nonrepudiation and authenticity of
information?
5. What type of functional security requirement involves Primary dataflow
receiving, processing, storing, transmitting, and deliv-
ering in report form?
6. Which nonfunctional security requirement provides a Logging
way to capture information correctly and a way to store
that information to help support later audits?
7. Which security concept refers to the quality of informa- Sensitivity
tion that could cause harm or damage if disclosed?
, WGU-C706 Secure Software Design (Pre-Assessment)
Study online at https://quizlet.com/_9pp8vc
8. Which technology would be an example of an injection SQL
flaw, according to the OWASP Top 10?
9. A company is creating a new software to track cus- Create multiple layers of
tomer balance and wants to design a secure applica- protection so that a sub-
tion. sequent layer provides
protection if a layer is
Which best practice should be applied? breached
10. A company is developing a secure software that has to Open design
be evaluated and tested by a large number of experts.
Which security principle should be applied?
11. Which type of TCP scanning indicates that a system TCP SYN scanning
is moving to the second phase in a three-way TCP
handshake?
12. Which evaluation technique provides invalid, unex- Fuzz testing
pected, or random data to the inputs of a computer
software program?
13. Which approach provides an opportunity to improve Software assurance matu-
the software development life cycle by tailoring the rity model (SAMM)
process to the specific risks facing the organization?
14. Which phase contains sophisticated software develop- Optimizing
ment processes that ensure that feedback from one
phase reaches to the previous phase to improve future
results?
15. The activities for compliance include ensuring collect- PIA
ed information is only used for intended purposes,