Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 3 out of 24 pages
Exam (elaborations)

WGU D487 Secure Software Design Exam 2025/2026 | Version 3 Test Bank | 100+ Questions with OWASP & NIST Rationales | OA Practice Exam

Document preview thumbnail
Preview 3 out of 24 pages

MASTER WGU D487 SECURE SOFTWARE DESIGN (VERSION 3) FOR THE 2025/2026 ACADEMIC YEAR! This comprehensive test bank features 100+ questions with answer keys that include concise security rationales citing current OWASP Top 10 and NIST standards—exactly what you need to pass your Objective Assessment and excel in cybersecurity. Unlike generic test banks, this resource is specifically tailored to WGU's Version 3 curriculum. Each question challenges your understanding of secure software design principles, while every rationale references current industry standards from OWASP and NIST, ensuring you're learning practical, real-world security practices that align with your OA and future career. WHAT MAKES THIS D487 RESOURCE ESSENTIAL: 100+ TARGETED QUESTIONS for WGU D487 Secure Software Design (Version 3, 2025/2026) OWASP & NIST-REFERENCED RATIONALES - Every answer includes current security standard citations VERSION-SPECIFIC CONTENT - Updated for Version 3 curriculum and assessment requirements OA-READY PRACTICE EXAM - Questions structured like the actual Objective Assessment CURRENT SECURITY STANDARDS - Covers OWASP Top 10 2021, NIST SP 800-53, and secure SDLC principles Stop struggling with outdated materials. Get the version-specific test bank that actually prepares you for the WGU D487 OA. Purchase now and master secure software design with confidence!

Content preview

1



WGU D487 Secure Software Design Exam
2025/2026 | Version 3 Test Bank | 100+
Questions with OWASP & NIST Rationales |
OA Practice Exam

1. Which activity appears first in a secure SDLC?
A. Penetration testing
B. Security requirements elicitation
C. Static code scanning
D. Deployment hardening
Answer: B
Rationale: NIST SP 800-64: security is cheapest and most effective when begun during
requirements ("shift-left").
2. The STRIDE acronym helps designers enumerate:
A. Security patterns
B. Threat categories
C. Cryptographic modes
D. Risk matrices
Answer: B
Rationale: STRIDE = Spoofing, Tampering, Repudiation, Information Disclosure, DoS,
Elevation of Privilege (OWASP Threat Modeling).
3. The primary goal of “Fail Securely” is that after any failure the system:
A. Reboots automatically
B. Returns an error code to the user
C. Remains in a safe state
D. Logs the stack trace
Answer: C
Rationale: OWASP design principle: default to a secure state on failure to deny attackers
an advantage.

, 2



4. Defense-in-depth is best described as:
A. Duplicate servers for HA
B. Multiple, layered security controls
C. Two-person code review
D. Encrypting every database column
Answer: B
Rationale: Layered controls ensure single failures don’t compromise the whole system
(NIST CSF).
5. The Open-Design principle states security must NOT depend on:
A. Strong crypto
B. Secrecy of the algorithm
C. Key confidentiality
D. Correct code
Answer: B
Rationale: Kerckhoffs/OWASP: assume attackers know the design; only keys must stay
secret.
6. Which authentication factor does a one-time SMS code represent?
A. Something you have
B. Something you are
C. Something you know
D. Somewhere you are
Answer: A
Rationale: The phone (SIM) is the possessed factor, per NIST SP 800-63B.
7. The best protection against SQL injection is:
A. Single quotes escaping
B. Stored procedures
C. Parameterized queries / prepared statements
D. Client-side validation
Answer: C
Rationale: Parameterization enforces separation between code and data, making
injection syntactically impossible (OWASP Top 10).
8. Which hashing scheme is currently recommended for passwords?
A. MD5 with salt

, 3



B. SHA-1 with pepper
C. bcrypt or Argon2 with per-user salt
D. RIPEMD-160
Answer: C
Rationale: Adaptive, CPU-hard algorithms resist parallel brute force; NIST SP 800-63B
approves such schemes.
9. Session fixation is best mitigated by:
A. Setting httpOnly flag
B. Regenerating session ID after login
C. Using 128-bit session tokens
D. Storing ID in local-storage
Answer: B
Rationale: Issuing a new unpredictable ID after authentication prevents attacker-supplied
IDs from being used (OWASP Cheat Sheet).
10. A digital signature gives the recipient confidence in:
A. Confidentiality
B. Integrity & origin
C. Availability
D. Perfect-forward secrecy
Answer: B
Rationale: Asymmetric signature verifies sender (non-repudiation) and that message
hasn’t been altered (NIST SP 800-89).
11. The “D” in DREAD risk scoring stands for:
A. Detection difficulty
B. Damage potential
C. Data classification
D. Deployment cost
Answer: B
Rationale: Microsoft DREAD: Damage, Reproducibility, Exploitability, Affected users,
Discoverability.
12. Which item is NOT part of a threat model diagram?
A. Data-flow arrows
B. Trust boundaries

Document information

Uploaded on
December 1, 2025
Number of pages
24
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers
$15.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
STUVIAACTUALEXAMS
3.5
(169)
Sold
1295
Followers
210
Items
9802
Last sold
7 hours ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions