Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Exam (elaborations)

WGU D487 Oa 2025 Test Bank 3 With 420 Questions And Correct Answers (100% Correct Verified Answers)

Rating
-
Sold
-
Pages
67
Grade
A+
Uploaded on
08-10-2025
Written in
2025/2026

This document provides the WGU D487 OA Exam 2025 Test Bank (Version 3) containing 420 verified multiple-choice questions with 100% correct answers and detailed rationales. It comprehensively covers key concepts in Secure Software Design and the Security Development Lifecycle (SDL), including threat modeling, STRIDE, OWASP SAMM, BSIMM, risk assessment, penetration testing, and code review principles. Each question includes the correct answer and an explanation, making it ideal for students preparing for the WGU D487 certification or seeking a deep understanding of secure coding and software assurance frameworks.

Show more Read less
Institution
WGU D487 Oa 2025
Course
WGU D487 Oa 2025

Content preview

WGU D487 Oa 2025 Test Bank 3 With 420 Questions And
Correct Answers (100% Correct Verified Answers)

Question 1
Which of the following best defines a "threat" in the context of secure
software design?
A) A weakness in the system that could be exploited.
B) An action or event that could compromise the security of a system.
C) The potential harm that results from a security vulnerability.
D) A control implemented to mitigate a risk.
E) The likelihood of an attack occurring.
Correct Answer: B) An action or event that could compromise the security of
a system
Rationale: A threat is a potential for harm or an action that could
exploit a vulnerability, leading to a negative impact on an asset or
system.

Question 2
What is the primary goal of "threat modeling" in the Secure Software
Development Lifecycle (SDL)?
A) To identify and fix all software bugs.
B) To estimate the cost of security incidents.
C) To proactively identify potential threats and vulnerabilities to a system.
D) To test the application's performance under heavy load.
E) To determine the market value of the software.
Correct Answer: C) To proactively identify potential threats and vulnerabilities
to a system
Rationale: Threat modeling is a structured approach to identify
potential threats, assess their severity, and determine appropriate
mitigations early in the development process.

Question 3
Which component of the STRIDE threat modeling methodology focuses on
preventing unauthorized access to data?

,A) Spoofing
B) Tampering
C) Repudiation
D) Information Disclosure
E) Denial of Service
Correct Answer: D) Information Disclosure
Rationale: Information Disclosure threats involve the unauthorized
exposure of information, which directly relates to preventing
unauthorized access to data.

Question 4
In a Data Flow Diagram (DFD), which symbol represents a process where
data is transformed or manipulated?
A) Square (External Entity)
B) Circle or Oval (Process)
C) Open-ended rectangle (Data Store)
D) Arrow (Data Flow)
E) Triangle (Trust Boundary)
Correct Answer: B) Circle or Oval (Process)
Rationale: In DFDs, a circle or oval typically represents a process,
which is an activity that transforms input data into output data.

Question 5
Which phase of the Security Development Lifecycle (SDL) is primarily
focused on identifying security requirements and potential risks early in the
design process?
A) Training
B) Requirements and Design
C) Implementation
D) Verification
E) Release and Response
Correct Answer: B) Requirements and Design

,Rationale: The Requirements and Design phase of the SDL is where
security is integrated from the ground up, including defining
security requirements, conducting threat modeling, and performing
security architecture reviews.

Question 6
Which secure coding principle aims to prevent buffer overflow attacks?
A) Input validation
B) Output encoding
C) Principle of least privilege
D) Secure defaults
E) Cryptographic key management
Correct Answer: A) Input validation
Rationale: Input validation is crucial for preventing buffer overflow
attacks by ensuring that input data does not exceed the size of the
allocated buffer, thus preventing malicious code injection.

Question 7
What is the primary purpose of a "static analysis" security test?
A) To analyze code while the application is running.
B) To identify vulnerabilities in code without executing the application.
C) To simulate real-world attacks by ethical hackers.
D) To verify that security controls are properly configured in a deployed
environment.
E) To measure the performance impact of security features.
Correct Answer: B) To identify vulnerabilities in code without executing the
application
Rationale: Static analysis (SAST) involves analyzing source code,
bytecode, or binary code without executing the program, looking for
coding errors that could lead to security vulnerabilities.

Question 8
Which OWASP Security Assurance Maturity Model (SAMM) domain focuses on

, activities related to managing and overseeing the overall security assurance
program?
A) Governance
B) Design
C) Implementation
D) Verification
E) Deployment
Correct Answer: A) Governance
Rationale: The Governance domain in OWASP SAMM covers activities
such as strategy and metrics, policy and compliance, and education
and guidance, focusing on the overarching management of the
security assurance program.

Question 9
A development team is implementing security requirements in an Agile
environment. When should security requirements be integrated into the
development process?
A) Only during the final testing phase.
B) Only after all functional requirements are complete.
C) Continuously throughout each sprint and iteration.
D) Once a year during a security audit.
E) Only by a dedicated security team at the end of the project.
Correct Answer: C) Continuously throughout each sprint and iteration
Rationale: In Agile, security should be integrated into every sprint
("every sprint requirements") to ensure it's built in from the start,
rather than being a last-minute add-on.

Question 10
Which risk mitigation strategy involves reducing the likelihood or impact of a
potential security threat?
A) Risk acceptance
B) Risk avoidance

Written for

Institution
WGU D487 Oa 2025
Course
WGU D487 Oa 2025

Document information

Uploaded on
October 8, 2025
Number of pages
67
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers

Subjects

$28.99
Get access to the full document:

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Get to know the seller

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
POLYCARP West Virginia University
View profile
Follow You need to be logged in order to follow users or courses
Sold
903
Member since
1 year
Number of followers
11
Documents
1190
Last sold
19 hours ago
The scholars desk

Struggling to find high-quality study materials? Look no further! I offer well-structured notes, summaries, essays, and research papers across various subjects, designed to help you understand concepts faster, improve your grades, and save study time What You’ll Find Here: ✔ Clear, concise, and exam-focused study materials ✔ Well-organized content for easy understanding ✔ Reliable resources to support your assignments and research ✔ Time-saving summaries to help you study efficiently Whether you\'re preparing for an exam, working on an assignment, or just need a quick reference, my materials are crafted to provide accurate, well-researched, and easy-to-grasp information Browse through my collection and take your studies to the next level!

Read more Read less
4.9

513 reviews

5
460
4
42
3
7
2
1
1
3

Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions