100% satisfaction guarantee Immediately available after payment Both online and in PDF No strings attached 4.2 TrustPilot
logo-home
Exam (elaborations)

WGU D487 Secure Software Design Exam 2025/2026 | Version 3 Test Bank | 100+ Questions with OWASP & NIST Rationales | OA Practice Exam

Rating
-
Sold
-
Pages
24
Grade
A+
Uploaded on
01-12-2025
Written in
2025/2026

MASTER WGU D487 SECURE SOFTWARE DESIGN (VERSION 3) FOR THE 2025/2026 ACADEMIC YEAR! This comprehensive test bank features 100+ questions with answer keys that include concise security rationales citing current OWASP Top 10 and NIST standards—exactly what you need to pass your Objective Assessment and excel in cybersecurity. Unlike generic test banks, this resource is specifically tailored to WGU's Version 3 curriculum. Each question challenges your understanding of secure software design principles, while every rationale references current industry standards from OWASP and NIST, ensuring you're learning practical, real-world security practices that align with your OA and future career. WHAT MAKES THIS D487 RESOURCE ESSENTIAL: 100+ TARGETED QUESTIONS for WGU D487 Secure Software Design (Version 3, 2025/2026) OWASP & NIST-REFERENCED RATIONALES - Every answer includes current security standard citations VERSION-SPECIFIC CONTENT - Updated for Version 3 curriculum and assessment requirements OA-READY PRACTICE EXAM - Questions structured like the actual Objective Assessment CURRENT SECURITY STANDARDS - Covers OWASP Top 10 2021, NIST SP 800-53, and secure SDLC principles Stop struggling with outdated materials. Get the version-specific test bank that actually prepares you for the WGU D487 OA. Purchase now and master secure software design with confidence!

Show more Read less
Institution
WGU D487 Secure Software Design
Course
WGU D487 Secure Software Design










Whoops! We can’t load your doc right now. Try again or contact support.

Written for

Institution
WGU D487 Secure Software Design
Course
WGU D487 Secure Software Design

Document information

Uploaded on
December 1, 2025
Number of pages
24
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers

Subjects

Content preview

1



WGU D487 Secure Software Design Exam
2025/2026 | Version 3 Test Bank | 100+
Questions with OWASP & NIST Rationales |
OA Practice Exam

1. Which activity appears first in a secure SDLC?
A. Penetration testing
B. Security requirements elicitation
C. Static code scanning
D. Deployment hardening
Answer: B
Rationale: NIST SP 800-64: security is cheapest and most effective when begun during
requirements ("shift-left").
2. The STRIDE acronym helps designers enumerate:
A. Security patterns
B. Threat categories
C. Cryptographic modes
D. Risk matrices
Answer: B
Rationale: STRIDE = Spoofing, Tampering, Repudiation, Information Disclosure, DoS,
Elevation of Privilege (OWASP Threat Modeling).
3. The primary goal of “Fail Securely” is that after any failure the system:
A. Reboots automatically
B. Returns an error code to the user
C. Remains in a safe state
D. Logs the stack trace
Answer: C
Rationale: OWASP design principle: default to a secure state on failure to deny attackers
an advantage.

, 2



4. Defense-in-depth is best described as:
A. Duplicate servers for HA
B. Multiple, layered security controls
C. Two-person code review
D. Encrypting every database column
Answer: B
Rationale: Layered controls ensure single failures don’t compromise the whole system
(NIST CSF).
5. The Open-Design principle states security must NOT depend on:
A. Strong crypto
B. Secrecy of the algorithm
C. Key confidentiality
D. Correct code
Answer: B
Rationale: Kerckhoffs/OWASP: assume attackers know the design; only keys must stay
secret.
6. Which authentication factor does a one-time SMS code represent?
A. Something you have
B. Something you are
C. Something you know
D. Somewhere you are
Answer: A
Rationale: The phone (SIM) is the possessed factor, per NIST SP 800-63B.
7. The best protection against SQL injection is:
A. Single quotes escaping
B. Stored procedures
C. Parameterized queries / prepared statements
D. Client-side validation
Answer: C
Rationale: Parameterization enforces separation between code and data, making
injection syntactically impossible (OWASP Top 10).
8. Which hashing scheme is currently recommended for passwords?
A. MD5 with salt

, 3



B. SHA-1 with pepper
C. bcrypt or Argon2 with per-user salt
D. RIPEMD-160
Answer: C
Rationale: Adaptive, CPU-hard algorithms resist parallel brute force; NIST SP 800-63B
approves such schemes.
9. Session fixation is best mitigated by:
A. Setting httpOnly flag
B. Regenerating session ID after login
C. Using 128-bit session tokens
D. Storing ID in local-storage
Answer: B
Rationale: Issuing a new unpredictable ID after authentication prevents attacker-supplied
IDs from being used (OWASP Cheat Sheet).
10. A digital signature gives the recipient confidence in:
A. Confidentiality
B. Integrity & origin
C. Availability
D. Perfect-forward secrecy
Answer: B
Rationale: Asymmetric signature verifies sender (non-repudiation) and that message
hasn’t been altered (NIST SP 800-89).
11. The “D” in DREAD risk scoring stands for:
A. Detection difficulty
B. Damage potential
C. Data classification
D. Deployment cost
Answer: B
Rationale: Microsoft DREAD: Damage, Reproducibility, Exploitability, Affected users,
Discoverability.
12. Which item is NOT part of a threat model diagram?
A. Data-flow arrows
B. Trust boundaries

Get to know the seller

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
STUVIASTUDYGUIDE University Of California - Los Angeles (UCLA)
Follow You need to be logged in order to follow users or courses
Sold
567
Member since
2 year
Number of followers
198
Documents
4001
Last sold
11 hours ago
STUVIASTUDYGUIDES

Join Thousands of successful students who use our study materials to boost their grades. With carefully crafted notes and well-researched guides, you're just a click away from mastering your courses. Study hard, study smart, and get the grades you deserve!

3,5

72 reviews

5
31
4
11
3
9
2
7
1
14

Recently viewed by you

Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their exams and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can immediately select a different document that better matches what you need.

Pay how you prefer, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card or EFT and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Frequently asked questions