EXAM (UPDATED 2025)
QUESTIONS & ANSWERS | LATEST
ALREADY GRADED A+ UPDATE 2025|
2026 D487 SECURE SW DESIGN
Which practice in the Ship A5 policy compliance analysis
(A5) phase of the security
development cycle verifies
whether the product meets
security mandates?
Which post-release support PRSA1: External vulnerability disclosure
activity defines the process response
to communicate, identify,
and alleviate security
threats?
What are two core practice Governance, Construction
areas of the OWASP
Security Assurance
Maturity Model
(OpenSAMM)?
,Which practice in the Ship (A5) phase
of the security
Vulnerability scan development cycle
uses tools to identify weaknesses in
the product?
Which post-release support activity should
be Security
architectural reviews completed when
companies are joining together?
, Which of the Ship (A5) deliverables of the
security Analyze
activities and standards development cycle
are performed during the A5 policy
compliance analysis?
Which of the Ship (A5) deliverables of the
security white-box
security test development cycle are
performed during the code-
assisted penetration testing?
Which of the Ship (A5) deliverables of
the security license
compliance development cycle are
performed during the open-
source licensing review?
Which of the Ship (A5) deliverables of
the security Release
and ship development cycle are
performed during the final
security review?
How can you establish your own SDL to
build security iterative
development into a process appropriate
for your organization's needs
based on agile?
How can you establish your own SDL to build security
continuous integration