Page |1
WGU D487 SECURE SW DESIGN EXAM 2 (VERSION A AND
B) 2025/2026 NEWEST ACTUAL EXAM WITH COMPLETE
QUESTIONS AND VERIFIED ANSWERS |ALREADY GRADED
A+|
An Agile development team is looking for a threat modeling
methodology that can be scaled across multiple projects and
easily visualized to align with their sprint cycles. Which
methodology would best support their requirements?
A) TRIKE
B) VAST
C) OCTAVE
D) PASTA - ANSWERS-B) VAST
A DevOps team has limited time to dedicate to complex threat
modeling but requires a methodology that integrates seamlessly
into their Agile workflow, with visual diagrams to simplify security
risk communication. What makes VAST a strong fit for this team?
, Page |2
A) VAST minimizes the need for visual aids
B) VAST provides simple and scalable visual diagrams, fitting
naturally into Agile workflows for continuous security evaluation
and communication
C) VAST is only focused on organizational risks, limiting
application-specific threat insights
D) VAST provides no visual components and requires complex
documentation - ANSWERS-B) VAST provides simple and
scalable visual diagrams, fitting naturally into Agile workflows for
continuous security evaluation and communication
Which threat modeling methodology is best suited for aligning
security efforts with business objectives through attack
simulation?
A) OCTAVE
B) VAST
C) PASTA
D) TRIKE - ANSWERS-C) PASTA
, Page |3
Which methodology is primarily audit-focused and designed to
provide consistent risk assessment results?
A) OCTAVE
B) TRIKE
C) Microsoft Threat Modeling
D) VAST - ANSWERS-B) TRIKE
What is a key advantage of the Microsoft Threat Modeling
methodology?
A) It uses the DREAD model exclusively
B) It is highly compatible with Agile development due to its
developer-focused, application-centric approach using STRIDE
C) It emphasizes external compliance over application security
D) It limits involvement to only security experts - ANSWERS-B) It
is highly compatible with Agile development due to its developer-
focused, application-centric approach using STRIDE
, Page |4
The VAST methodology is particularly suitable for which type of
development environment?
A) Regulatory-heavy, traditional environments
B) Agile environments requiring scalability and visualization of
threats
C) High-security enterprises focused solely on organizational risk
D) Small teams with no need for visual models - ANSWERS-B)
Agile environments requiring scalability and visualization of
threats
A large organization with dedicated security resources is looking
for a threat modeling methodology that focuses on organizational
risks and allows them to assess security practices across
departments. Which methodology would best meet these needs?
A) OCTAVE
B) PASTA
C) TRIKE
D) Microsoft Threat Modeling - ANSWERS-A) OCTAVE
WGU D487 SECURE SW DESIGN EXAM 2 (VERSION A AND
B) 2025/2026 NEWEST ACTUAL EXAM WITH COMPLETE
QUESTIONS AND VERIFIED ANSWERS |ALREADY GRADED
A+|
An Agile development team is looking for a threat modeling
methodology that can be scaled across multiple projects and
easily visualized to align with their sprint cycles. Which
methodology would best support their requirements?
A) TRIKE
B) VAST
C) OCTAVE
D) PASTA - ANSWERS-B) VAST
A DevOps team has limited time to dedicate to complex threat
modeling but requires a methodology that integrates seamlessly
into their Agile workflow, with visual diagrams to simplify security
risk communication. What makes VAST a strong fit for this team?
, Page |2
A) VAST minimizes the need for visual aids
B) VAST provides simple and scalable visual diagrams, fitting
naturally into Agile workflows for continuous security evaluation
and communication
C) VAST is only focused on organizational risks, limiting
application-specific threat insights
D) VAST provides no visual components and requires complex
documentation - ANSWERS-B) VAST provides simple and
scalable visual diagrams, fitting naturally into Agile workflows for
continuous security evaluation and communication
Which threat modeling methodology is best suited for aligning
security efforts with business objectives through attack
simulation?
A) OCTAVE
B) VAST
C) PASTA
D) TRIKE - ANSWERS-C) PASTA
, Page |3
Which methodology is primarily audit-focused and designed to
provide consistent risk assessment results?
A) OCTAVE
B) TRIKE
C) Microsoft Threat Modeling
D) VAST - ANSWERS-B) TRIKE
What is a key advantage of the Microsoft Threat Modeling
methodology?
A) It uses the DREAD model exclusively
B) It is highly compatible with Agile development due to its
developer-focused, application-centric approach using STRIDE
C) It emphasizes external compliance over application security
D) It limits involvement to only security experts - ANSWERS-B) It
is highly compatible with Agile development due to its developer-
focused, application-centric approach using STRIDE
, Page |4
The VAST methodology is particularly suitable for which type of
development environment?
A) Regulatory-heavy, traditional environments
B) Agile environments requiring scalability and visualization of
threats
C) High-security enterprises focused solely on organizational risk
D) Small teams with no need for visual models - ANSWERS-B)
Agile environments requiring scalability and visualization of
threats
A large organization with dedicated security resources is looking
for a threat modeling methodology that focuses on organizational
risks and allows them to assess security practices across
departments. Which methodology would best meet these needs?
A) OCTAVE
B) PASTA
C) TRIKE
D) Microsoft Threat Modeling - ANSWERS-A) OCTAVE