WGU D487 Secure Software Design EXAM WITH 100% RATED CORRECT
REAL EXAM QUESTIONS AND CORRECT ANSWERS| GRADED A+
|2025 LATEST VERSION | 100% VERIFIED
Which practice in the Ship (A5) phase of the security development cycle verifies whether the
product meets security mandates? - (answer)A5 policy compliance analysis
Which post-release support activity defines the process to communicate, identify, and alleviate
security threats? - (answer)PRSA1: External vulnerability disclosure response
What are two core practice areas of the OWASP Security Assurance Maturity Model
(OpenSAMM)? - (answer)Governance, Construction
Which practice in the Ship (A5) phase of the security development cycle uses tools to identify
weaknesses in the product? - (answer)Vulnerability scan
Which post-release support activity should be completed when companies are joining together? -
(answer)Security architectural reviews
Which of the Ship (A5) deliverables of the security development cycle are performed during the
A5 policy compliance analysis? - (answer)Analyze activities and standards
Which of the Ship (A5) deliverables of the security development cycle are performed during the
code-assisted penetration testing? - (answer)white-box security test
,Which of the Ship (A5) deliverables of the security development cycle are performed during the
open-source licensing review? - (answer)license compliance
Which of the Ship (A5) deliverables of the security development cycle are performed during the
final security review? - (answer)Release and ship
How can you establish your own SDL to build security into a process appropriate for your
organization's needs based on agile? - (answer)iterative development
How can you establish your own SDL to build security into a process appropriate for your
organization's needs based on devops? - (answer)continuous integration and continuous
deployments
How can you establish your own SDL to build security into a process appropriate for your
organization's needs based on cloud? - (answer)API invocation processes
How can you establish your own SDL to build security into a process appropriate for your
organization's needs based on digital enterprise? - (answer)enables and improves business
activities
Which phase of penetration testing allows for remediation to be performed? - (answer)Deploy
Which key deliverable occurs during post-release support? - (answer)third-party reviews
,Which business function of OpenSAMM is associated with governance? - (answer)Policy and
compliance
Which business function of OpenSAMM is associated with construction? - (answer)Threat
assessment
Which business function of OpenSAMM is associated with verification? - (answer)Code review
Which business function of OpenSAMM is associated with deployment? - (answer)Vulnerability
management
What is the product risk profile? - (answer)A security assessment deliverable that estimates the
actual cost of the product.
A software security team member has been tasked with creating a deliverable that provides
details on where and to what degree sensitive customer information is collected, stored, or
created within a new product offering. What does the team member need to deliver in order to
meet the objective? - (answer)Privacy impact assessment
What is the first phase in the security development life cycle? - (answer)A1 Security Assessment
What are the three areas of compliance requirements? - (answer)Legal, financial, and industry
standards
, What term refers to how the system should function based on the environment in which the
system will operate? - (answer)operational requirements
During what phase of SDL do all key stakeholders discuss, identify, and have common
understandings of the security and privacy implications, considerations, and requirements? -
(answer)A1 Security Assessment
What are the three areas of focus in secure software requirements? - (answer)Gathering the
software requirements, data classification, and managing data protection requirements
During what phase of SDL is an initial project outline for security milestones developed and
integrated into the development project schedule? - (answer)A1 Security Assessment
What term means requirements that describe what the system will do and its core purpose? -
(answer)functional requirements
What term means requirements that describe any constraints or restrictions on a design but do
not impact the core purpose of the system - (answer)non-functional requirements
What term is a process that evaluates issues and privacy impact rating in relation to the privacy
of personally identifiable information in the software? - (answer)privacy impact assessment
What term helps to determine the actual cost of the product from different perspectives? -
(answer)product risk profile
REAL EXAM QUESTIONS AND CORRECT ANSWERS| GRADED A+
|2025 LATEST VERSION | 100% VERIFIED
Which practice in the Ship (A5) phase of the security development cycle verifies whether the
product meets security mandates? - (answer)A5 policy compliance analysis
Which post-release support activity defines the process to communicate, identify, and alleviate
security threats? - (answer)PRSA1: External vulnerability disclosure response
What are two core practice areas of the OWASP Security Assurance Maturity Model
(OpenSAMM)? - (answer)Governance, Construction
Which practice in the Ship (A5) phase of the security development cycle uses tools to identify
weaknesses in the product? - (answer)Vulnerability scan
Which post-release support activity should be completed when companies are joining together? -
(answer)Security architectural reviews
Which of the Ship (A5) deliverables of the security development cycle are performed during the
A5 policy compliance analysis? - (answer)Analyze activities and standards
Which of the Ship (A5) deliverables of the security development cycle are performed during the
code-assisted penetration testing? - (answer)white-box security test
,Which of the Ship (A5) deliverables of the security development cycle are performed during the
open-source licensing review? - (answer)license compliance
Which of the Ship (A5) deliverables of the security development cycle are performed during the
final security review? - (answer)Release and ship
How can you establish your own SDL to build security into a process appropriate for your
organization's needs based on agile? - (answer)iterative development
How can you establish your own SDL to build security into a process appropriate for your
organization's needs based on devops? - (answer)continuous integration and continuous
deployments
How can you establish your own SDL to build security into a process appropriate for your
organization's needs based on cloud? - (answer)API invocation processes
How can you establish your own SDL to build security into a process appropriate for your
organization's needs based on digital enterprise? - (answer)enables and improves business
activities
Which phase of penetration testing allows for remediation to be performed? - (answer)Deploy
Which key deliverable occurs during post-release support? - (answer)third-party reviews
,Which business function of OpenSAMM is associated with governance? - (answer)Policy and
compliance
Which business function of OpenSAMM is associated with construction? - (answer)Threat
assessment
Which business function of OpenSAMM is associated with verification? - (answer)Code review
Which business function of OpenSAMM is associated with deployment? - (answer)Vulnerability
management
What is the product risk profile? - (answer)A security assessment deliverable that estimates the
actual cost of the product.
A software security team member has been tasked with creating a deliverable that provides
details on where and to what degree sensitive customer information is collected, stored, or
created within a new product offering. What does the team member need to deliver in order to
meet the objective? - (answer)Privacy impact assessment
What is the first phase in the security development life cycle? - (answer)A1 Security Assessment
What are the three areas of compliance requirements? - (answer)Legal, financial, and industry
standards
, What term refers to how the system should function based on the environment in which the
system will operate? - (answer)operational requirements
During what phase of SDL do all key stakeholders discuss, identify, and have common
understandings of the security and privacy implications, considerations, and requirements? -
(answer)A1 Security Assessment
What are the three areas of focus in secure software requirements? - (answer)Gathering the
software requirements, data classification, and managing data protection requirements
During what phase of SDL is an initial project outline for security milestones developed and
integrated into the development project schedule? - (answer)A1 Security Assessment
What term means requirements that describe what the system will do and its core purpose? -
(answer)functional requirements
What term means requirements that describe any constraints or restrictions on a design but do
not impact the core purpose of the system - (answer)non-functional requirements
What term is a process that evaluates issues and privacy impact rating in relation to the privacy
of personally identifiable information in the software? - (answer)privacy impact assessment
What term helps to determine the actual cost of the product from different perspectives? -
(answer)product risk profile