100% satisfaction guarantee Immediately available after payment Both online and in PDF No strings attached 4.6 TrustPilot
logo-home
Exam (elaborations)

D487 Secure SW Design Questions and Correct Answers/ Latest Update / Already Graded

Rating
-
Sold
1
Pages
20
Grade
A+
Uploaded on
23-04-2025
Written in
2024/2025

D487 Secure SW Design Questions and Correct Answers/ Latest Update / Already Graded D487 Secure SW Design Questions and Correct Answers/ Latest Update / Already Graded D487 Secure SW Design Questions and Correct Answers/ Latest Update / Already Graded

Show more Read less
Institution
D487
Course
D487










Whoops! We can’t load your doc right now. Try again or contact support.

Written for

Institution
D487
Course
D487

Document information

Uploaded on
April 23, 2025
Number of pages
20
Written in
2024/2025
Type
Exam (elaborations)
Contains
Questions & answers

Subjects

Content preview

1 | Page
D487 Secure SW Design Questions and Correct
Answers/ Latest Update / Already Graded
Which practice in the Ship (A5) phase of the security development cycle verifies
whether the product meets security mandates?

Ans: A5 policy compliance analysis


Which post-release support activity defines the process to communicate, identify,
and alleviate security threats?

Ans: PRSA1: External vulnerability disclosure response


What are two core practice areas of the OWASP Security Assurance Maturity
Model (OpenSAMM)?

Ans: Governance, Construction


Which practice in the Ship (A5) phase of the security development cycle uses tools
to identify weaknesses in the product?

Ans: Vulnerability scan


Which post-release support activity should be completed when companies are
joining together?

Ans: Security architectural reviews


Which of the Ship (A5) deliverables of the security development cycle are
performed during the A5 policy compliance analysis?

Ans: Analyze activities and standards


Which of the Ship (A5) deliverables of the security development cycle are
performed during the code-assisted penetration testing?

, 2 | Page
Ans: white-box security test


Which of the Ship (A5) deliverables of the security development cycle are
performed during the open-source licensing review?

Ans: license compliance


Which of the Ship (A5) deliverables of the security development cycle are
performed during the final security review?

Ans: Release and ship


How can you establish your own SDL to build security into a process appropriate
for your organization's needs based on agile?

Ans: iterative development


How can you establish your own SDL to build security into a process appropriate
for your organization's needs based on devops?

Ans: continuous integration and continuous deployments


How can you establish your own SDL to build security into a process appropriate
for your organization's needs based on cloud?

Ans: API invocation processes


How can you establish your own SDL to build security into a process appropriate
for your organization's needs based on digital enterprise?

Ans: enables and improves business activities


Which phase of penetration testing allows for remediation to be performed?

Ans: Deploy

, 3 | Page
Which key deliverable occurs during post-release support?

Ans: third-party reviews


Which business function of OpenSAMM is associated with governance?

Ans: Policy and compliance


Which business function of OpenSAMM is associated with construction?

Ans: Threat assessment


Which business function of OpenSAMM is associated with verification?

Ans: Code review


Which business function of OpenSAMM is associated with deployment?

Ans: Vulnerability management


What is the product risk profile?

Ans: A security assessment deliverable that estimates the actual cost of the
product.


A software security team member has been tasked with creating a deliverable that
provides details on where and to what degree sensitive customer information is
collected, stored, or created within a new product offering. What does the team
member need to deliver in order to meet the objective?

Ans: Privacy impact assessment


What is the first phase in the security development life cycle?

Ans: A1 Security Assessment

Get to know the seller

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
Expert1 Chamberlian School of Nursing
View profile
Follow You need to be logged in order to follow users or courses
Sold
41
Member since
11 months
Number of followers
1
Documents
7286
Last sold
5 days ago
Expert1

Welcome to Expert1 – Your Trusted Study Partner! Struggling to prepare for exams or ace your coursework? At Expert1, I provide top-tier, exam-ready study materials designed to help you succeed with confidence. All notes are created with clarity, precision, and a deep understanding of the curriculum to ensure you save time and score high. What You’ll Find Here: High-quality summaries and exam packs Past paper solutions with detailed explanations Notes aligned with your syllabus (A-levels, university, etc.) Resources from top-performing students Trusted by hundreds of students to boost their grades!

Read more Read less
4.3

6 reviews

5
5
4
0
3
0
2
0
1
1

Recently viewed by you

Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Frequently asked questions