100% satisfaction guarantee Immediately available after payment Both online and in PDF No strings attached 4.2 TrustPilot
logo-home
Exam (elaborations)

D487 SECURE SOFTWARE DESIGN EXAMINATION TEST 2026 VERIFIED QUESTIONS AND SOLUTIONS ALREADY PASSED

Rating
-
Sold
-
Pages
16
Grade
A+
Uploaded on
06-11-2025
Written in
2025/2026

D487 SECURE SOFTWARE DESIGN EXAMINATION TEST 2026 VERIFIED QUESTIONS AND SOLUTIONS ALREADY PASSED

Institution
D487 SECURE SOFTWARE DESIGN
Course
D487 SECURE SOFTWARE DESIGN










Whoops! We can’t load your doc right now. Try again or contact support.

Written for

Institution
D487 SECURE SOFTWARE DESIGN
Course
D487 SECURE SOFTWARE DESIGN

Document information

Uploaded on
November 6, 2025
Number of pages
16
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers

Subjects

Content preview

D487 SECURE SOFTWARE DESIGN
EXAMINATION TEST 2026 VERIFIED QUESTIONS
AND SOLUTIONS ALREADY PASSED

◉ Threat Modeling (Stages). Answer: 1. Identify Assets: Determine
what needs to be protected.
2. Identify Threats: Identify potential threats to those assets.
3. Identify Vulnerabilities: Analyze weaknesses that could be
exploited by threats.
4. Assess Risks: Evaluate the likelihood and impact of identified
threats exploiting vulnerabilities.
5. Mitigate Risks: Implement countermeasures to reduce or
eliminate identified risks


◉ PASTA Stages. Answer: - Define Objectives: Establish goals and
scope of the analysis.
- Create an Application Diagram: Visualize the application and its
components.
- Identify Threat Profiles: Define potential attacker personas and
their motivations.
- Analyze Threats: Assess how attackers could exploit vulnerabilities
to achieve their objectives.

,- Prioritize Threats: Rank threats based on their severity and
likelihood.
- Mitigate Threats: Develop and implement countermeasures to
address identified threats.


◉ Core OpenSAMM activities. Answer: Governance
Construction
Verification
Deployment


◉ static analysis. Answer: Source code of an application is reviewed
manually or with automatic tools without running the code


◉ dynamic analysis. Answer: Analysis and testing of a program
occurs while it is being executed or run


◉ Fuzzing. Answer: Injection of randomized data into a software
program in an attempt to find system failures, memory leaks, error
handling issues, and improper input validation


◉ OWASP ZAP. Answer: -Open-source web application security
scanner-Can be used as a proxy to manipulate traffic running
through it (even https)

, ◉ ISO/IEC 27001. Answer: Specifies requirements for establishing,
implementing, operating, monitoring, reviewing, maintaining and
improving a documented information security management system


◉ ISO/IEC 17799. Answer: ISO/EIC is a joint committee that
develops and maintains standards in the IT industry. 17799 is an
international code of practice for information security management.
This section defines confidentiality, integrity and availability
controls.


◉ ISO/IEC 27034. Answer: A standard that provides guidance to
help organizations embed security within their processes that help
secure applications running in the environment, including
application lifecycle processes


◉ Software security champion. Answer: a developer with an interest
in security who helps amplify the security message at the team level


◉ waterfall methodology. Answer: a sequential, activity-based
process in which each phase in the SDLC is performed sequentially
from planning through implementation and maintenance


◉ Agile Development. Answer: A software development
methodology that delivers functionality in rapid iterations,
measured in weeks, requiring frequent communication,
development, testing, and delivery.

Get to know the seller

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
FocusFile7 Harvard University
View profile
Follow You need to be logged in order to follow users or courses
Sold
28
Member since
6 months
Number of followers
2
Documents
15687
Last sold
18 hours ago
FocusFile7

Welcome to FocusFile, your inspiring hub for academic excellence! Just like your favorite café where every sip brings comfort, FocusFile is designed to be your go-to space for clear thinking, deep focus, and study success. Here at FocusFile, I believe learning isn’t just about cramming it’s about clarity, growth, and building the confidence to conquer any challenge. That’s why you’ll find a handpicked collection of top-notch, easy-to-digest study materials, smart summaries, and guides tailored to a wide range of subjects and learning styles. Whether you're gearing up for exams, brushing up on class notes, or just need that extra push, FocusFile has you covered. From quick-reference sheets to deep-dive notes, there’s something here for every learner whether you're a visual thinker, a bullet-point lover, or someone who thrives on quick, impactful insights. Think of FocusFile as your academic sanctuary, a place where productivity meets peace of mind. So grab your favorite drink, settle in, and let’s sharpen your focus and fuel your success, one file at a time. Thanks for making FocusFile your study partner. Let’s unlock your full potential together!

Read more Read less
4.0

3 reviews

5
1
4
1
3
1
2
0
1
0

Recently viewed by you

Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Frequently asked questions