1
WGU D487 SECURE SW DESIGN OA EXAM 2025
ACTUAL EXAM COMPLETE ACCURATE EXAM
QUESTIONS WITH DETAILED VERIFIED ANSWERS
Which post-release PRSA1: External vulnerability disclosure response
support activity
defines the process
to communicate,
identify, and
alleviate security
threats?
What are two core Governance, Construction
practice areas of the
OWASP Security
Assurance Maturity
Model
(OpenSAMM)?
Which practice in the Vulnerability scan
Ship (A5) phase of the
security
development cycle uses
tools to identify
weaknesses in the
product?
,2
Which post-release Security architectural reviews
support activity
should be completed
when companies are
joining together?
Which of the Ship (A5) Analyze activities and standards
deliverables of the
security development
cycle are performed
during the A5 policy
compliance analysis?
Which of the Ship (A5) white-box security test
deliverables of the
security
development cycle
are performed
during the code-
assisted penetration
testing?
Which of the Ship (A5) license compliance
deliverables of the
security
development cycle
are performed
during the open-
source licensing
review?
Which of the Ship (A5) Release and ship
deliverables of the
security
development cycle
are performed
during the final
security review?
, 3
How can you establish iterative development
your own SDL to build
security into a
process appropriate for
your organization's
needs based on agile?
How can you establish continuous integration and continuous deployments
your own SDL to build
security into a
process appropriate for
your organization's
needs based on devops?
WGU D487 SECURE SW DESIGN OA EXAM 2025
ACTUAL EXAM COMPLETE ACCURATE EXAM
QUESTIONS WITH DETAILED VERIFIED ANSWERS
Which post-release PRSA1: External vulnerability disclosure response
support activity
defines the process
to communicate,
identify, and
alleviate security
threats?
What are two core Governance, Construction
practice areas of the
OWASP Security
Assurance Maturity
Model
(OpenSAMM)?
Which practice in the Vulnerability scan
Ship (A5) phase of the
security
development cycle uses
tools to identify
weaknesses in the
product?
,2
Which post-release Security architectural reviews
support activity
should be completed
when companies are
joining together?
Which of the Ship (A5) Analyze activities and standards
deliverables of the
security development
cycle are performed
during the A5 policy
compliance analysis?
Which of the Ship (A5) white-box security test
deliverables of the
security
development cycle
are performed
during the code-
assisted penetration
testing?
Which of the Ship (A5) license compliance
deliverables of the
security
development cycle
are performed
during the open-
source licensing
review?
Which of the Ship (A5) Release and ship
deliverables of the
security
development cycle
are performed
during the final
security review?
, 3
How can you establish iterative development
your own SDL to build
security into a
process appropriate for
your organization's
needs based on agile?
How can you establish continuous integration and continuous deployments
your own SDL to build
security into a
process appropriate for
your organization's
needs based on devops?