DESIGN EXAM LATEST 2025 ACTUAL EXAM 400 QUESTIONS
AND CORRECT DETAILED ANSWERS WITH RATIONALES
(VERIFIED ANSWERS) |ALREADY GRADED A+
What is a step for constructing a threat model for a project when using practical risk analysis?
A Align your business goals
B Apply engineering methods
C Estimate probability of project time
D Make a list of what you are trying to protect - ANSWER-D
Which cyber threats are typically surgical by nature, have highly specific targeting, and are
technologically sophisticated?
A Tactical attacks
B Criminal attacks
C Strategic attacks
D User-specific attacks - ANSWER-A
Which type of cyberattacks are often intended to elevate awareness of a topic?
A Cyberwarfare
B Tactical attacks
C User-specific attacks
D Sociopolitical attacks - ANSWER-D
What type of attack locks a user's desktop and then requires a payment to unlock it?
A Phishing
, WGU MASTER'S COURSE C706 - SECURE SOFTWARE
DESIGN EXAM LATEST 2025 ACTUAL EXAM 400 QUESTIONS
AND CORRECT DETAILED ANSWERS WITH RATIONALES
(VERIFIED ANSWERS) |ALREADY GRADED A+
B Keylogger
C Ransomware
D Denial-of-service - ANSWER-C
What is a countermeasure against various forms of XML and XML path injection attacks?
A XML name wrapping
B XML unicode encoding
C XML attribute escaping
D XML distinguished name escaping - ANSWER-C
Which countermeasure is used to mitigate SQL injection attacks?
A SQL Firewall
B Projected bijection
C Query parameterization
D Progressive ColdFusion - ANSWER-C
What is an appropriate countermeasure to an escalation of privilege attack?
A Enforcing strong password policies
B Using standard encryption algorithms and correct key sizes
C Enabling the auditing and logging of all administration activities
D Restricting access to specific operations through role-based access controls - ANSWER-D
, WGU MASTER'S COURSE C706 - SECURE SOFTWARE
DESIGN EXAM LATEST 2025 ACTUAL EXAM 400 QUESTIONS
AND CORRECT DETAILED ANSWERS WITH RATIONALES
(VERIFIED ANSWERS) |ALREADY GRADED A+
Which configuration management security countermeasure implements least privilege access control?
A Following strong password policies to restrict access
B Restricting file access to users based on authorization
C Avoiding clear text format for credentials and sensitive data
D Using AES 256 encryption for communications of a sensitive nature - ANSWER-B
Which dphase dof dthe dsoftware ddevelopment dlife dcycle d(SDL/SDLC) dwould dbe dused dto
ddetermine dthe dminimum dset dof dprivileges drequired dto dperform dthe dtargeted dtask dand
drestrict dthe duser dto da ddomain dwith dthose dprivileges?
A dDesign
B dDeploy
C dDevelopment
D dImplementation d- dANSWER-A
Which dleast dprivilege dmethod dis dmore dgranular din dscope dand dgrants dspecific dprocesses donly
dthe dprivileges dnecessary dto dperform dcertain drequired dfunctions, dinstead dof dgranting dthem
dunrestricted daccess dto dthe dsystem?
A dEntitlement dprivilege
B dSeparation dof dprivilege
C dAggregation dof dprivileges
D dSegregation dof dresponsibilities d- dANSWER-B
Why ddoes dprivilege dcreep dpose da dpotential dsecurity drisk?
, WGU dMASTER'S dCOURSE dC706 d- dSECURE dSOFTWARE
dDESIGN dEXAM dLATEST d2025 dACTUAL dEXAM d400
dQUESTIONS dAND dCORRECT dDETAILED dANSWERS dWITH
dRATIONALES d(VERIFIED dANSWERS) d|ALREADY dGRADED
dA+
A dUser dprivileges ddo dnot dmatch dtheir djob drole.
B dWith dmore dprivileges, dthere dare dmore dresponsibilities.
C dAuditing dwill dshow da dmismatch dbetween dindividual dresponsibilities dand dtheir daccess drights.
D dUsers dhave dmore dprivileges dthan dthey dneed dand dmay dperform dactions doutside dtheir djob
ddescription. d- dANSWER-D
A dsystem ddeveloper dis dimplementing da dnew dsales dsystem. dThe dsystem ddeveloper dis dconcerned dthat
dunauthorized dindividuals dmay dbe dable dto dview dsensitive dcustomer dfinancial ddata.
Which dfamily dof dnonfunctional drequirements dshould dbe dconsidered das dpart dof dthe dacceptance
dcriteria?
A dIntegrity
B dAvailability
C dNonrepudition
D dConfidentiality d- dANSWER-D
A dproject dmanager dis dgiven dthe dtask dto dcome dup dwith dnonfunctional dacceptance dcriteria
drequirements dfor dbusiness downers das dpart dof da dproject ddelivery.
Which dnonfunctional drequirement dshould dbe dapplied dto dthe dacceptance dcriteria?
A dGive dsearch doptions dto dusers
B dEvaluate dtest dexecution dresults
C dDivide dusers dinto dgroups dand dgive dthem dseparate drights
D dDevelop dsoftware dthat dkeeps ddownward dcompatibility dintact d- dANSWER-B