WGU D487 Secure Software Design 2025
Actual Exam – Versions A & B | 100% Verified
Questions and Expert-Reviewed Correct
Answers | Graded A+ Guaranteed
Secure SDLC (20 Questions)
Question 1
In which phase of the SDLC does the team identify product risks and create a security milestone
outline?
A. Design phase
B. Security Assessment (A1) phase
C. Implementation phase
D. Testing phase
Correct Answer: B
Rationale: The Security Assessment (A1) phase involves identifying product risks and outlining
security milestones to integrate security into the SDLC.
Question 2
Which SDLC phase involves deploying the software to the production environment?
A. Maintenance phase
B. Deployment phase
C. Testing phase
D. Requirements phase
Correct Answer: B
Rationale: The Deployment phase pushes the software to production, making it accessible to
users.
Question 3
What is the primary purpose of the Security Development Life Cycle (SDL)?
A. Replace the SDLC
B. Ensure secure software through integrated security practices
C. Focus solely on post-release support
D. Eliminate the need for testing
Correct Answer: B
Rationale: The SDL is a security overlay on the SDLC, embedding best practices to develop
secure applications.
,Question 4
Which activity occurs during the End of Life phase of the SDLC?
A. Writing initial code
B. Secure removal of the application from systems
C. Conducting penetration testing
D. Gathering requirements
Correct Answer: B
Rationale: The End of Life phase involves securely decommissioning the application to prevent
data leaks.
Question 5
What is a key difference between the SDL and SDLC?
A. SDL focuses only on coding, SDLC on testing
B. SDL integrates security practices across SDLC phases
C. SDLC replaces SDL in Agile environments
D. SDL eliminates the need for requirements gathering
Correct Answer: B
Rationale: The SDL enhances the SDLC by integrating security activities, not replacing it.
Question 6
Which SDLC phase involves verifying that software meets functional requirements in a
controlled environment?
A. Design phase
B. Testing phase
C. Implementation phase
D. Deployment phase
Correct Answer: B
Rationale: The Testing phase validates software functionality and security in a controlled
setting.
Question 7
What is a key deliverable of the SDL project outline?
A. Estimating product cost
B. Mapping security activities to the development schedule
C. Writing initial code
D. Deploying to production
Correct Answer: B
Rationale: The SDL project outline aligns security tasks with the SDLC schedule.
Question 8
, Which SDLC phase focuses on preparing technical requirements for software design?
A. Requirements phase
B. Design phase
C. Testing phase
D. Maintenance phase
Correct Answer: B
Rationale: The Design phase translates requirements into technical specifications.
Question 9
What is a primary focus of the Maintenance phase in the SDLC?
A. Writing initial code
B. Continuous monitoring for security issues
C. Defining business requirements
D. Conducting threat modeling
Correct Answer: B
Rationale: The Maintenance phase involves ongoing monitoring and updates for security and
functionality.
Question 10
Which practice in the Ship (A5) phase verifies compliance with security mandates?
A. Vulnerability scan
B. A5 policy compliance analysis
C. Code review
D. Penetration testing
Correct Answer: B
Rationale: A5 policy compliance analysis ensures the product meets security standards.
Question 11
What is a key responsibility of the Software Security Architect in the SDL?
A. Writing user stories
B. Providing technical leadership for security planning
C. Conducting user acceptance testing
D. Managing sprint ceremonies
Correct Answer: B
Rationale: The Software Security Architect drives security planning and architecture.
Question 12
Which SDL activity involves assessing resource availability?
A. Design phase
B. Security Assessment (A1) phase
C. Testing phase
D. Deployment phase
Actual Exam – Versions A & B | 100% Verified
Questions and Expert-Reviewed Correct
Answers | Graded A+ Guaranteed
Secure SDLC (20 Questions)
Question 1
In which phase of the SDLC does the team identify product risks and create a security milestone
outline?
A. Design phase
B. Security Assessment (A1) phase
C. Implementation phase
D. Testing phase
Correct Answer: B
Rationale: The Security Assessment (A1) phase involves identifying product risks and outlining
security milestones to integrate security into the SDLC.
Question 2
Which SDLC phase involves deploying the software to the production environment?
A. Maintenance phase
B. Deployment phase
C. Testing phase
D. Requirements phase
Correct Answer: B
Rationale: The Deployment phase pushes the software to production, making it accessible to
users.
Question 3
What is the primary purpose of the Security Development Life Cycle (SDL)?
A. Replace the SDLC
B. Ensure secure software through integrated security practices
C. Focus solely on post-release support
D. Eliminate the need for testing
Correct Answer: B
Rationale: The SDL is a security overlay on the SDLC, embedding best practices to develop
secure applications.
,Question 4
Which activity occurs during the End of Life phase of the SDLC?
A. Writing initial code
B. Secure removal of the application from systems
C. Conducting penetration testing
D. Gathering requirements
Correct Answer: B
Rationale: The End of Life phase involves securely decommissioning the application to prevent
data leaks.
Question 5
What is a key difference between the SDL and SDLC?
A. SDL focuses only on coding, SDLC on testing
B. SDL integrates security practices across SDLC phases
C. SDLC replaces SDL in Agile environments
D. SDL eliminates the need for requirements gathering
Correct Answer: B
Rationale: The SDL enhances the SDLC by integrating security activities, not replacing it.
Question 6
Which SDLC phase involves verifying that software meets functional requirements in a
controlled environment?
A. Design phase
B. Testing phase
C. Implementation phase
D. Deployment phase
Correct Answer: B
Rationale: The Testing phase validates software functionality and security in a controlled
setting.
Question 7
What is a key deliverable of the SDL project outline?
A. Estimating product cost
B. Mapping security activities to the development schedule
C. Writing initial code
D. Deploying to production
Correct Answer: B
Rationale: The SDL project outline aligns security tasks with the SDLC schedule.
Question 8
, Which SDLC phase focuses on preparing technical requirements for software design?
A. Requirements phase
B. Design phase
C. Testing phase
D. Maintenance phase
Correct Answer: B
Rationale: The Design phase translates requirements into technical specifications.
Question 9
What is a primary focus of the Maintenance phase in the SDLC?
A. Writing initial code
B. Continuous monitoring for security issues
C. Defining business requirements
D. Conducting threat modeling
Correct Answer: B
Rationale: The Maintenance phase involves ongoing monitoring and updates for security and
functionality.
Question 10
Which practice in the Ship (A5) phase verifies compliance with security mandates?
A. Vulnerability scan
B. A5 policy compliance analysis
C. Code review
D. Penetration testing
Correct Answer: B
Rationale: A5 policy compliance analysis ensures the product meets security standards.
Question 11
What is a key responsibility of the Software Security Architect in the SDL?
A. Writing user stories
B. Providing technical leadership for security planning
C. Conducting user acceptance testing
D. Managing sprint ceremonies
Correct Answer: B
Rationale: The Software Security Architect drives security planning and architecture.
Question 12
Which SDL activity involves assessing resource availability?
A. Design phase
B. Security Assessment (A1) phase
C. Testing phase
D. Deployment phase