Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 3 out of 24 pages
Exam (elaborations)

SECURE SOFTWARE DESIGN - C706 EXAM QUESTIONS AND ANSWERS. VERIFIED 2025/2026.

Document preview thumbnail
Preview 3 out of 24 pages

SECURE SOFTWARE DESIGN - C706 EXAM QUESTIONS AND ANSWERS. VERIFIED 2025/2026.

Content preview

SECURE SOFTWARE DESIGN - C706
EXAM QUESTIONS AND ANSWERS.
VERIFIED 2025/2026.




Protecting the software and the systems on which it runs after release, after dev is complete -
ANS Application security



Three core elements of security - ANS Confidentiality, integrity, and availability (the C.I.A.
model



Tools that look for a fixed set of patterns or rules in the code in a manner similar to virus-
checking programs - ANS Static analysis tools



Ensures that the user has the appropriate role and privilege to view data - ANS Authorization



Ensures that the user is who he or she claims to be and that the data come from the
appropriate place - ANS Authentication



Question 4 :




1 @COPYRIGHT 2025/2026 ALLRIGHTS RESERVED.

,What is responsible for preserving authorized restrictions on information access and disclosure,
including means for protecting personal privacy and proprietary information? - ANS Question
4



Confidentiality



Q5:



What is responsible for guarding against improper information modification or destruction, and
includes ensuring information non-repudiation and authenticity? - ANS Q5:



Integrity



Q6:



Which concept in the software life cycle understands the potential security threats to the
system, determines risk, and establishes appropriate mitigations? - ANS Q6:



Threat modeling



Q7:



The idea behind is simply to understand the potential security threats to the system, determine
risk, and establish appropriate mitigations. When it is performed correctly, it occurs early in the
project life cycle and can be used to find security design issues before code is committed. -
ANS Q7:



threat modeling

2 @COPYRIGHT 2025/2026 ALLRIGHTS RESERVED.

, _Q8:



____________is about building secure software: designing software to be secure; making sure
that software is secure; and educating software developers, architects, and users about how to
build security in. - ANS Q8:



software security



Q9:



__________, as the name suggests, is really aimed at developing secure software, not
necessarily quality software - ANS Q9:



SDL methodology



The most well-known SDL model is the __________, a process that Microsoft has adopted for
the development of software that needs to withstand malicious attack. This is considered the
most mature of the top three models. - ANS Trustworthy Computing Security Development
Lifecycle



_________This is a study of real-world software security initiatives organized so that you can
determine where you stand with your software security initiative and how to evolve your efforts
over time. It is a set of best practices that Cigital developed by analyzing real-world data from
nine leading software security initiatives and creating a framework based on common areas of
success. There are 12 practices organized into four domains. These practices are used to
organize the 109 BSIMM activities (BSIMM 4 has a total of 111 activities). - ANS BSIMM (
short for Building Security In Maturity Model.)




3 @COPYRIGHT 2025/2026 ALLRIGHTS RESERVED.

Document information

Uploaded on
December 9, 2025
Number of pages
24
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers
$12.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
sirjoel
3.6
(18)
Sold
133
Followers
13
Items
12780
Last sold
2 months ago




Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions