https://www.stuvia.com/user/Smartscroll
WGU-C706 Secure Software Design (Pre-Assessment)
and Terms exam with correct answers 2025,pass
assured.A+graded.
Which due diligence activity for supply chain security should occur in the initiation phase of the software
b b b b b b b b b b b b b b b b
acquisition life cycle?
b b b
-Facilitating knowledge transfer between suppliers
b b b b
-Lessening the risk of disseminating information during disposal
b b b b b b b
-Mitigating supply chain security risk by providing user guidance
b b b b b b b b
-Developing a request for proposal (RFP) that includes supply chain security risk management - CORRECT
b b b b b b b b b b b b b b
ANSWER✔✔Developing a request for proposal (RFP) that includes supply chain security risk management
b b b b b b b b b b b b b
Which due diligence activity for supply chain security investigates the means by which data sets are shared
b b b b b b b b b b b b b b b b
and assessed?
b b
-An on-site assessment
b b
-A process policy review
b b b
-A third-party assessment
b b
-A document exchange and review - CORRECT ANSWER✔✔A document exchange and review
b b b b b b b b b b b
,https://www.stuvia.com/user/Smartscroll
Identification of the entity making the access request
b b b b b b b
Verification that the request has not changed since its initiation
b b b b b b b b b
Application of the appropriate authorization procedures
b b b b b
Reexamination of previously authorized requests by the same entity
b b b b b b b b
Which security design analysis is being described?
b b b b b b
-Open design b
-Complete mediation b
-Economy of mechanism b b
-Least common mechanism - CORRECT ANSWER✔✔Complete mediation
b b b b b b
Which software security principle guards against the improper modification or destruction of information
b b b b b b b b b b b b
and ensures the nonrepudiation and authenticity of information?
b b b b b b b b
-Quality
-Integrity
-Availability
-Confidentiality - CORRECT ANSWER✔✔Integrity b b b
What type of functional security requirement involves receiving, processing, storing, transmitting, and
b b b b b b b b b b b
delivering in report form?
b b b b
-Logging
-Error handling
b
-Primary dataflow b
, https://www.stuvia.com/user/Smartscroll
-Access control flow - CORRECT ANSWER✔✔Primary dataflow
b b b b b b
Which nonfunctional security requirement provides a way to capture information correctly and a way to
b b b b b b b b b b b b b b
store that information to help support later audits? - CORRECT ANSWER✔✔Logging
b b b b b b b b b b b
Which type of TCP scanning indicates that a system is moving to the second phase in a three-way TCP
b b b b b b b b b b b b b b b b b b
handshake?
b
-TCP SYN scanning
b b
-TCP ACK scanning
b b
-TCP XMAS scanning
b b
-TCP Connect scanning - CORRECT ANSWER✔✔TCP SYN scanning
b b b b b b b
A company is creating a new software to track customer balance and wants to design a secure application.
b b b b b b b b b b b b b b b b b b
Which best practice should be applied? - CORRECT ANSWER✔✔Create multiple layers of protection so
b b b b b b b b b b b b b
that a subsequent layer provides protection if a layer is breached
b b b b b b b b b b b
A company is developing a secure software that has to be evaluated and tested by a large number of
b b b b b b b b b b b b b b b b b b
experts.
b b
Which security principle should be applied?
b b b b b
-Fail safe
b
-Open design b
-Defense in depth b b
-Complete mediation - CORRECT ANSWER✔✔Open design
b b b b b
WGU-C706 Secure Software Design (Pre-Assessment)
and Terms exam with correct answers 2025,pass
assured.A+graded.
Which due diligence activity for supply chain security should occur in the initiation phase of the software
b b b b b b b b b b b b b b b b
acquisition life cycle?
b b b
-Facilitating knowledge transfer between suppliers
b b b b
-Lessening the risk of disseminating information during disposal
b b b b b b b
-Mitigating supply chain security risk by providing user guidance
b b b b b b b b
-Developing a request for proposal (RFP) that includes supply chain security risk management - CORRECT
b b b b b b b b b b b b b b
ANSWER✔✔Developing a request for proposal (RFP) that includes supply chain security risk management
b b b b b b b b b b b b b
Which due diligence activity for supply chain security investigates the means by which data sets are shared
b b b b b b b b b b b b b b b b
and assessed?
b b
-An on-site assessment
b b
-A process policy review
b b b
-A third-party assessment
b b
-A document exchange and review - CORRECT ANSWER✔✔A document exchange and review
b b b b b b b b b b b
,https://www.stuvia.com/user/Smartscroll
Identification of the entity making the access request
b b b b b b b
Verification that the request has not changed since its initiation
b b b b b b b b b
Application of the appropriate authorization procedures
b b b b b
Reexamination of previously authorized requests by the same entity
b b b b b b b b
Which security design analysis is being described?
b b b b b b
-Open design b
-Complete mediation b
-Economy of mechanism b b
-Least common mechanism - CORRECT ANSWER✔✔Complete mediation
b b b b b b
Which software security principle guards against the improper modification or destruction of information
b b b b b b b b b b b b
and ensures the nonrepudiation and authenticity of information?
b b b b b b b b
-Quality
-Integrity
-Availability
-Confidentiality - CORRECT ANSWER✔✔Integrity b b b
What type of functional security requirement involves receiving, processing, storing, transmitting, and
b b b b b b b b b b b
delivering in report form?
b b b b
-Logging
-Error handling
b
-Primary dataflow b
, https://www.stuvia.com/user/Smartscroll
-Access control flow - CORRECT ANSWER✔✔Primary dataflow
b b b b b b
Which nonfunctional security requirement provides a way to capture information correctly and a way to
b b b b b b b b b b b b b b
store that information to help support later audits? - CORRECT ANSWER✔✔Logging
b b b b b b b b b b b
Which type of TCP scanning indicates that a system is moving to the second phase in a three-way TCP
b b b b b b b b b b b b b b b b b b
handshake?
b
-TCP SYN scanning
b b
-TCP ACK scanning
b b
-TCP XMAS scanning
b b
-TCP Connect scanning - CORRECT ANSWER✔✔TCP SYN scanning
b b b b b b b
A company is creating a new software to track customer balance and wants to design a secure application.
b b b b b b b b b b b b b b b b b b
Which best practice should be applied? - CORRECT ANSWER✔✔Create multiple layers of protection so
b b b b b b b b b b b b b
that a subsequent layer provides protection if a layer is breached
b b b b b b b b b b b
A company is developing a secure software that has to be evaluated and tested by a large number of
b b b b b b b b b b b b b b b b b b
experts.
b b
Which security principle should be applied?
b b b b b
-Fail safe
b
-Open design b
-Defense in depth b b
-Complete mediation - CORRECT ANSWER✔✔Open design
b b b b b