- Study guides, Class notes & Summaries
Looking for the best study guides, study notes and summaries about ? On this page you'll find 89 study documents about .
89 results
Exam (elaborations)
C706 Practice Exam From Assessment Questions And Answers Rated 100% Correct!!
Which due diligence activity for supply chain security should occur in the initiation phase of the 
software acquisition life cycle? 
-Facilitating knowledge transfer between suppliers 
-Lessening the risk of disseminating information during disposal 
-Mitigating supply chain security risk by providing user guidance 
-Developing a request for proposal (RFP) that includes supply chain security risk management - 
Answer -Developing a request for proposal (RFP) that includes supply chain security r...
Exam (elaborations)
C706 Test Prep Questions With 100% Correct Solutions.
AGILE - 1. Short releases 
2. Delayed design 
3. Involve users along the way 
4. Minimal documentation 
5. Informal/frequent documentation 
6. Constant change 
Why AGILE? - 1. shorten development cycles 
2. adaptability 
3. more efficient; less duplication 
AGILE Methodologies - 1. Extreme Programming (XP) 
2. Crystal 
3. Unified Process 
4. Scrum 
5. Open Source 
Extreme Programming (XP) Core Values - 1. Frequent communication between team and 
customer 
2. Simplicity in design and code 
3. Sma...
Exam (elaborations)
Secure Software Design Study Guide - C706
Confidentiality - Information is not made available or disclosed to unauthorized individuals, entities, or processes. Ensures unauthorized persons are not able to read private and sensitive data. It is achieved through cryptography. 
 
Integrity - Ensures unauthorized persons or channels are not able to modify the data. It is accomplished through the use of a message digest or digital signatures. 
 
Availability - The computing systems used to store and process information, the security controls...
Exam (elaborations)
Secure Software Design Study Guide - C706
Secure Software Design Study Guide - C706
Exam (elaborations)
WGU Master's Course C706 Secure Software Design Questions and Answers
WGU Master's Course C706 Secure Software Design Questions and Answers
Exam (elaborations)
C706 - Chapter 20 EXAM GUIDE GRADED A+ WITH COMPLETE SOLUTIONS
What is a denial-of-service attack? 
An attack that prevent the system from receiving, processing, or responding to legitimate traffic or requests for resources and objects 
 
 
 
What is spoofing attack? 
The attacker pretends to be someone or something other than whom they are. They can spoof identities, IP addresses, email addresses, and phone numbers. They often replace the valid source and /or destination IP address and node numbers with false ones. 
 
 
 
What are countermeasures to spoofi...
Exam (elaborations)
WGU MSCSIA C706 Chapters 1 -4 GRADED A+ EXAM WITH 100% CORRECT ANSWERS
Confidentiality 
means that the private and sensitive data handled by the application cannot be read by anyone who is not explicitly authorized to view it. 
 
 
 
Intregrity 
means that the data processed by an application is not modified by any unauthorized channels or any unauthorized persons. 
 
 
 
Availability 
the system's ability to remain operational even in the face of failure or attack. 
 
 
 
Cleartext or Plaintext 
information that is not encrypted. 
 
 
 
Ciphertext 
information th...
Exam (elaborations)
C706 - CHAPTER 5 -- DESIGN AND DEVELOPMENT (A3)
Design & Development (A3) Stage 
A3 Policy compliance analysis 
Security test plan composition 
Static Analysis 
Threat model updating 
Design security analysis and review 
Privacy implementation assessment 
 
 
 
During this phase, any policy that exists outside the domain of the SDL policy is reviewed and might include policies from outside the development organization that set security and privacy requirements and guidelines to be adhered to when developing software or applications. What is t...
Exam (elaborations)
C706 SECURE SOFTWARE DESIGN & SDLC 100% SOLVED QUESTIONS ALREADY GRADED A+
Define maintenance 
updating software systems to improve or correct them 
 
 
 
Define incident response plan 
the documented steps to follow when system attack or failure occurs 
 
 
 
What 8 elements should an incident response plan document? 
- monitoring duties for production software 
- a definition for incidents; 
- a contact for incidents; 
- emergency contact for priority incidents; 
- a clear escalation chain 
- software shutdown procedures 
- attack specific procedures 
- security docs...
Exam (elaborations)
SECURE SOFTWARE DESIGN - C706 EXAM GUIDE
What is the Secure Development Lifecycle? 
Secure Development Lifecycle. The SDL is the sum of tools, people, models, methodologies, blueprints, metrics that help make systems/software secure. It is focused on baking security into the software/system. 
 
 
What is the TCSDL 
The trustworthy Computing Security Development Lifecycle was designed by Microsoft and adopted for the development of software needed to withstand attacks. 
 
 
Explain BSIMM. 
Building Security in Maturity Model is a softwa...
Exam (elaborations)
WGU-C706 SECURE SOFTWARE DESIGN (LESSON 20 CISSP) QITH 100% CORRECT ANSWERS|UPDATED&VERIFIED
Prioritize security over other requirements. 
Which one of the following is not a principle of Agile development? 
 
 
 
Foreign key 
Which one of the following key types is used to enforce referential integrity between database tables? 
 
 
 
Gantt 
What type of chart provides a graphical illustration of a schedule that helps to plan, coordinate, and track project tasks? 
 
 
 
Isolation 
What transaction management principle ensures that two transactions do not interfere with each other as the...
Exam (elaborations)
WGU-C706 SECURE SOFTWARE DESIGN (LESSON 21 CISSP) 100% SOLVED UPDATED&VERIFIED EXAM
Which one of the following types of attacks relies on the difference between the timing of two events? 
TOCTOU 
 
 
 
What technique may be used to limit the effectiveness of rainbow table attacks? 
Salting 
 
 
 
What character should always be treated carefully when encountered as user input on a web form? 
' 
 
 
 
What type of virus utilizes more than one propagation technique to maximize the number of penetrated systems? 
Multipartite virus 
 
 
 
What advanced virus technique modifies the...
Exam (elaborations)
C706 - SECURE SOFTWARE DESIGN EXAM GUIDE WITH 100% CORRECT ANSWERS|GUARANTEED SUCCESS
Complete Mediation 
Every request by a subject to access an object in a computer system must undergo a valid and effective authorization procedure 
Entails: (a) identification of the entity making the access request; (b) verification that the request has not changed since its initiation; (c) application of the appropriate authorization procedures; and (d) reexamination of previously authorized requests by the same entity. 
 
 
 
Open Design 
an open-access control system design that has been eva...
Exam (elaborations)
SECURE SOFTWARE DESIGN - C706 WITH COMPLETE SOLUTIONS GRADED A+
Protecting the software and the systems on which it runs after release, after dev is complete 
Application security 
 
 
 
Three core elements of security 
Confidentiality, integrity, and availability (the C.I.A. model 
 
 
 
Tools that look for a fixed set of patterns or rules in the code in a manner similar to virus-checking programs 
Static analysis tools 
 
 
 
Ensures that the user has the appropriate role and privilege to view data 
Authorization 
 
 
 
Ensures that the user is who he or s...
Exam (elaborations)
C706 - SECURE SOFTWARE DESIGN - STUDY GUIDE (REDDIT) GRADED A+ WITH COMPLETE SOLUTIONS
Confidentiality 
In information security, confidentiality "is the property, that information is not made available or 
disclosed to unauthorized individuals, entities, or processes" 
 
 
 
Integrity 
In information security, data integrity means maintaining and assuring the accuracy and completeness of data over its entire life-cycle. This means that data cannot be modified in an unauthorized or undetected manner. This can be also used to validate databases to make sure none of the data is cor...
Exam (elaborations)
C706 - SECURE SOFTWARE DESIGN 2023/24 UPDATE
ISO/IEC 27034-1:2011 
A standard for application security which offers a concise, internationally recognized way to get transparency into a vendor/supplier's software security management process 
 
ISO/IEC 27034 standard provides guidance to help organizations embed security within their processes that help secure applications running in the environment, including application life cycle processes. 
 
 
 
Trustworthy Computing Security Development Lifecycle 
The most widely used security develop...
Exam (elaborations)
C706 PRACTICE EXAM FROM ASSESSMENT WITH COMPLETE SOLUTIONS GRADED A+
Which due diligence activity for supply chain security should occur in the initiation phase of the software acquisition life cycle? 
-Facilitating knowledge transfer between suppliers 
-Lessening the risk of disseminating information during disposal 
-Mitigating supply chain security risk by providing user guidance 
-Developing a request for proposal (RFP) that includes supply chain security risk management 
-Developing a request for proposal (RFP) that includes supply chain security risk manage...
Exam (elaborations)
C706 WGU|GRADED A WITH COMPLETE SOLUTIONS 202/24 UPDATE
Open Design Security Principle 
security of a mechanism should not depend on the secrecy of its design or implementation 
 
 
 
Strategic attacks 
user general targeting against a broad industry. highly repeatable and 
 
 
 
Tactical attacks 
surgical by nature, have highly specific targeting, and are technologically sophisticated 
 
 
 
User specific attacks 
can be strategic, tactical, or personal in nature, and target personal devices that may be either consumer or enterprise owned. 
 
 
 
So...
Exam (elaborations)
SECURE SOFTWARE DESIGN C706 - TEST PREP QUESTIONS 2023/24 UPDATE WITH COMPLETE SOLUTIONS
Which statement is true of a software development life cycle? 
 
A 
Workload testing should be performed while designing the functional requirements. 
B 
Parallel testing verifies whether more than one system is available for redundancy. 
C 
A software programmer should be the only person to develop the software, test it, and submit it to production 
D 
Unit testing should be performed by the developer and the quality assurance team. 
Answer D is correct. 
 
Unit testing should be performed by t...
Exam (elaborations)
C706 SECURE SOFTWARE DESIGN TERMS GRADED A+
access control 
The restriction of persons or programs that may access specific information. There are two default policies for this: allow by exception or deny by exception. 
 
 
 
Access Control List (ACL) 
The list of persons or programs that are allowed (or, in the case of blacklisting, not allowed) to access a particular resource. 
 
 
 
Access List Traffic-Based Security plan (ALTBS) 
A network with no other security measures in place besides a router-based access control list. 
 
 
 
Acti...