WGU D487 CORE MAIN QUESTIONS AND ANSWERS
SET A+
✔✔Which shape indicates each type of flow diagram element? - Data Store - ✔✔Two
Parallel horizontal lines
✔✔Which shape indicates each type of flow diagram element? - Data Flow - ✔✔Solid
Line with an arrow
✔✔Which shape indicates each type of flow diagram element? - Trust Boundry -
✔✔Dashed Line
✔✔What are the two deliverables of the Architecture phase of the SDL? - ✔✔Threat
Modeling artifacts & Policy compliance analysis
✔✔What SDL security assessment deliverable is used as an input to an SDL
architecture process? - ✔✔Threat profile
✔✔Which software security testing technique tests the software from an external
perspective? - ✔✔Black box
✔✔Which security design principle states that an entity should be given the minimum
privileges and resources for a minimum period of time for a task? - ✔✔Least privilege
✔✔After the developer is done coding a functionality, when should code review be
completed? - ✔✔Within hours or the same day
✔✔What is the order that code reviews should follow in order to be effective? - Step 1 -
✔✔Identify security code review objectives
✔✔What is the order that code reviews should follow in order to be effective? - Step 2 -
✔✔Preform preliminary scan
, ✔✔What is the order that code reviews should follow in order to be effective? - Step 3 -
✔✔Review code for security issues
✔✔What is the order that code reviews should follow in order to be effective? - Step 4 -
✔✔Review for security issues unique to the architecture
✔✔When a software application handles personally identifiable information (PII) data,
what will be the Privacy Impact Rating? - ✔✔P1: High privacy risk
✔✔Which key success factor identifies threats to the software? - ✔✔Effective threat
modeling
✔✔What is the goal of design security review deliverables? - ✔✔To make modifications
to the design of software components based on security assessments
✔✔Which application scanner component is useful in identifying vulnerabilities such as
cookie misconfigurations and insecure configuration of HTTP response headers? -
✔✔Passive scanner
✔✔Which type of attack occurs when an attacker uses malicious code in the data sent
in a form? - ✔✔Cross-site scripting
✔✔Which tools provide the given functions? - Self Managed Automatic Code Review
Product - ✔✔SonarQube
✔✔Which tools provide the given functions? - Proprietary issue tracking product -
✔✔JIRA
✔✔Which tools provide the given functions? - Open-source automation server -
✔✔Jenkins
✔✔Which tools provide the given functions? - AI-Powered managemnt soltuion -
✔✔Dynatrace
✔✔A new application is released, and users perform initial testing on the application.
Which type of testing are the users performing? - ✔✔Beta Testing
✔✔What is a non-system-related component in software security testing attack surface
validation? - ✔✔Users
SET A+
✔✔Which shape indicates each type of flow diagram element? - Data Store - ✔✔Two
Parallel horizontal lines
✔✔Which shape indicates each type of flow diagram element? - Data Flow - ✔✔Solid
Line with an arrow
✔✔Which shape indicates each type of flow diagram element? - Trust Boundry -
✔✔Dashed Line
✔✔What are the two deliverables of the Architecture phase of the SDL? - ✔✔Threat
Modeling artifacts & Policy compliance analysis
✔✔What SDL security assessment deliverable is used as an input to an SDL
architecture process? - ✔✔Threat profile
✔✔Which software security testing technique tests the software from an external
perspective? - ✔✔Black box
✔✔Which security design principle states that an entity should be given the minimum
privileges and resources for a minimum period of time for a task? - ✔✔Least privilege
✔✔After the developer is done coding a functionality, when should code review be
completed? - ✔✔Within hours or the same day
✔✔What is the order that code reviews should follow in order to be effective? - Step 1 -
✔✔Identify security code review objectives
✔✔What is the order that code reviews should follow in order to be effective? - Step 2 -
✔✔Preform preliminary scan
, ✔✔What is the order that code reviews should follow in order to be effective? - Step 3 -
✔✔Review code for security issues
✔✔What is the order that code reviews should follow in order to be effective? - Step 4 -
✔✔Review for security issues unique to the architecture
✔✔When a software application handles personally identifiable information (PII) data,
what will be the Privacy Impact Rating? - ✔✔P1: High privacy risk
✔✔Which key success factor identifies threats to the software? - ✔✔Effective threat
modeling
✔✔What is the goal of design security review deliverables? - ✔✔To make modifications
to the design of software components based on security assessments
✔✔Which application scanner component is useful in identifying vulnerabilities such as
cookie misconfigurations and insecure configuration of HTTP response headers? -
✔✔Passive scanner
✔✔Which type of attack occurs when an attacker uses malicious code in the data sent
in a form? - ✔✔Cross-site scripting
✔✔Which tools provide the given functions? - Self Managed Automatic Code Review
Product - ✔✔SonarQube
✔✔Which tools provide the given functions? - Proprietary issue tracking product -
✔✔JIRA
✔✔Which tools provide the given functions? - Open-source automation server -
✔✔Jenkins
✔✔Which tools provide the given functions? - AI-Powered managemnt soltuion -
✔✔Dynatrace
✔✔A new application is released, and users perform initial testing on the application.
Which type of testing are the users performing? - ✔✔Beta Testing
✔✔What is a non-system-related component in software security testing attack surface
validation? - ✔✔Users