WGU D487 SOFTWARE COMPREHENSIVE
QUESTIONS AND ANSWERS SET A+
✔✔What is a list of information security vulnerabilities that aims to provide names for
publicly known problems? -✔✔Common computer vulnerabilities and exposures (CVE)
✔✔Which secure coding best practice uses well-tested, publicly available algorithms to
hide product data from unauthorized access? -✔✔Cryptographic practices
✔✔Which secure coding best practice uses well-tested, publicly available algorithms to
hide product data from unauthorized access? -✔✔Cryptographic practices
✔✔Which secure coding best practice ensures servers, frameworks, and system
components are all running the latest approved versions? -✔✔System configuration
✔✔Which secure coding best practice says to use parameterized queries, encrypted
connection strings stored in separate configuration files, and strong passwords or multi-
factor authentication? -✔✔Database security
✔✔Which secure coding best practice says that all information passed to other systems
should be encrypted? -✔✔Communication security
✔✔eam members are being introduced during sprint zero in the project kickoff meeting.
The person being introduced is a member of the scrum team, responsible for writing
feature logic and attending sprint ceremonies. Which role is the team member playing? -
✔✔Software developer
✔✔A software security team member has created data flow diagrams, chosen the
STRIDE methodology to perform threat reviews, and created the security assessment
for the new product. Which category of secure software best practices did the team
member perform? -✔✔Architecture analysis
, ✔✔Team members are being introduced during sprint zero in the project kickoff
meeting. The person being introduced will be a facilitator, will try to remove roadblocks
and ensure the team is communicating freely, and will be responsible for facilitating all
scrum ceremonies. Which role is the team member playing? -✔✔Scrum master
✔✔The new product standards state that all traffic must be secure and encrypted. What
is the name for this secure coding practice? -✔✔Communication security
✔✔Which DREAD category is based on how easily a threat exploit can be repeated? -
✔✔Reproducibility
✔✔Which mitigation technique can be used to fight against a data tampering threat? -
✔✔Digital signatures
✔✔What is a countermeasure to the web application security frame (ASF) configuration
management threat category? -✔✔Compliance requirement
✔✔Which type of requirement specifies that file formats the application sends to
financial institutions must be certified every four years? -✔✔Compliance requirement
✔✔Which type of requirement specifies that credit card numbers displayed in the
application will be masked so they only show the last four digits? -✔✔Privacy
requirement
✔✔Which type of requirement specifies that user passwords will require a minimum of 8
characters and must include at least one uppercase character, one number, and one
special character? -✔✔Security requirement
✔✔Which type of requirement specifies that credit card numbers are designated as
highly sensitive confidential personal information? -✔✔Data classification requirement
✔✔Which privacy impact statement requirement type defines how personal information
is protected on devices used by more than a single associate? -✔✔Privacy control
requirements
✔✔In which step of the PASTA threat modeling methodology does design flaw analysis
take place? -✔✔Vulnerability and weakness analysis
✔✔Which privacy impact statement requirement type defines who has access to
personal information within the product? -✔✔Access requirements
QUESTIONS AND ANSWERS SET A+
✔✔What is a list of information security vulnerabilities that aims to provide names for
publicly known problems? -✔✔Common computer vulnerabilities and exposures (CVE)
✔✔Which secure coding best practice uses well-tested, publicly available algorithms to
hide product data from unauthorized access? -✔✔Cryptographic practices
✔✔Which secure coding best practice uses well-tested, publicly available algorithms to
hide product data from unauthorized access? -✔✔Cryptographic practices
✔✔Which secure coding best practice ensures servers, frameworks, and system
components are all running the latest approved versions? -✔✔System configuration
✔✔Which secure coding best practice says to use parameterized queries, encrypted
connection strings stored in separate configuration files, and strong passwords or multi-
factor authentication? -✔✔Database security
✔✔Which secure coding best practice says that all information passed to other systems
should be encrypted? -✔✔Communication security
✔✔eam members are being introduced during sprint zero in the project kickoff meeting.
The person being introduced is a member of the scrum team, responsible for writing
feature logic and attending sprint ceremonies. Which role is the team member playing? -
✔✔Software developer
✔✔A software security team member has created data flow diagrams, chosen the
STRIDE methodology to perform threat reviews, and created the security assessment
for the new product. Which category of secure software best practices did the team
member perform? -✔✔Architecture analysis
, ✔✔Team members are being introduced during sprint zero in the project kickoff
meeting. The person being introduced will be a facilitator, will try to remove roadblocks
and ensure the team is communicating freely, and will be responsible for facilitating all
scrum ceremonies. Which role is the team member playing? -✔✔Scrum master
✔✔The new product standards state that all traffic must be secure and encrypted. What
is the name for this secure coding practice? -✔✔Communication security
✔✔Which DREAD category is based on how easily a threat exploit can be repeated? -
✔✔Reproducibility
✔✔Which mitigation technique can be used to fight against a data tampering threat? -
✔✔Digital signatures
✔✔What is a countermeasure to the web application security frame (ASF) configuration
management threat category? -✔✔Compliance requirement
✔✔Which type of requirement specifies that file formats the application sends to
financial institutions must be certified every four years? -✔✔Compliance requirement
✔✔Which type of requirement specifies that credit card numbers displayed in the
application will be masked so they only show the last four digits? -✔✔Privacy
requirement
✔✔Which type of requirement specifies that user passwords will require a minimum of 8
characters and must include at least one uppercase character, one number, and one
special character? -✔✔Security requirement
✔✔Which type of requirement specifies that credit card numbers are designated as
highly sensitive confidential personal information? -✔✔Data classification requirement
✔✔Which privacy impact statement requirement type defines how personal information
is protected on devices used by more than a single associate? -✔✔Privacy control
requirements
✔✔In which step of the PASTA threat modeling methodology does design flaw analysis
take place? -✔✔Vulnerability and weakness analysis
✔✔Which privacy impact statement requirement type defines who has access to
personal information within the product? -✔✔Access requirements