WGU D487 SECURE SOFTWARE CORRECT FINAL
EXAM QUESTIONS AND ANSWERS SET A+
✔✔An organizational security review discovered multiple database instances that were
installed using publicly available default settings, including security and access. How
should the organization remediate this vulnerability? -✔✔Ensure default accounts and
passwords are disabled or removed
✔✔During penetration testing, an analyst discovered a DOM-based (document object
model) cross-site scripting vulnerability within the applications search bar that could
allow an attacker to insert malicious code. How should the organization remediate this
vulnerability? -✔✔Enforce encoding of special characters
✔✔Application credentials are stored in the database using simple hashes to store
passwords. An undiscovered credential recovery flaw allowed a security analyst to
download the database and expose passwords using their GPU to crack the simple
encryption. How should the organization remediate this vulnerability? -✔✔Enforce the
use of strong, salted hashing functions when storing passwords
✔✔During functional testing, a QA analyst using a non-admin account caused an
application exception. After the exception was handled, the tester was able to navigate
to the admin section of the application by typing the URL directly into the browser
address bar. They were unable to force the same navigation before the exception was
thrown. How should the organization remediate this vulnerability? -✔✔Ensure user
privileges are restored to the appropriate level after exceptions
✔✔The product security incident response team (PSIRT) determined a reported
vulnerability was credible and of a high enough severity that it needs to be fixed. What
is the response team's next step? -✔✔Identify resources and schedule the fix
✔✔Organizational leadership is considering buying a competitor and has asked the
software security team to develop a plan to ensure the competitor's point-of-sale system
, complies with organizational policies. Which post-release deliverable is being
described? -✔✔Security strategy for M&A products
✔✔The software security team has been tasked with identifying who will be involved
when security vulnerabilities are reported from external entities. They are creating a
RACI matrix that will identify stakeholders by who is responsible, accountable,
consulted, and informed of any new vulnerabilities. Which post-release deliverable is
being described? -✔✔External vulnerability disclosure response process
✔✔After determining a reported vulnerability was a credible claim, the product security
incident response team (PSIRT) worked with development teams to create and test a
patch. The patch is scheduled to be released at the end of the month.What is the
response team's next step? -✔✔Notify customers that the fix is available
✔✔The organization is moving from a waterfall to an agile software development
methodology, so the software security group must adapt the security development life
cycle as well. They have decided to break out security requirements and deliverables to
fit better in the iterative life cycle by defining every-sprint requirements, one-time
requirements, bucket requirements, and final security review requirements. Which type
of requirement states that all user input values must be validated by type, size, and
range? -✔✔Every-sprint requirement
✔✔The software security group is conducting a maturity assessment using the Building
Security in Maturity Model (BSIMM). They are currently focused on reviewing security
testing results from recently completed initiatives.Which BSIMM domain is being
assessed? -✔✔Software security development life cycle (SSDL) touchpoints
✔✔The organization is moving from a waterfall to an agile software development
methodology, so the software security group must adapt the security development life
cycle as well. They have decided to break out security requirements and deliverables to
fit better in the iterative life cycle by defining every-sprint requirements, one-time
requirements, bucket requirements, and final security review requirements. Which type
of requirement states that the team must perform remote procedure call (RPC) fuzz
testing? -✔✔Bucket requirement
✔✔ What is a study of real-world software security initiatives organized so companies
can measure their initiatives and understand how to evolve them over time?, -
✔✔Building Security In Maturity Model (BSIMM)
✔✔What is the analysis of computer software that is performed without executing
programs? -✔✔Static analysis
✔✔Which International Organization for Standardization (ISO) standard is the
benchmark for information security today? -✔✔ISO/IEC 27001.
EXAM QUESTIONS AND ANSWERS SET A+
✔✔An organizational security review discovered multiple database instances that were
installed using publicly available default settings, including security and access. How
should the organization remediate this vulnerability? -✔✔Ensure default accounts and
passwords are disabled or removed
✔✔During penetration testing, an analyst discovered a DOM-based (document object
model) cross-site scripting vulnerability within the applications search bar that could
allow an attacker to insert malicious code. How should the organization remediate this
vulnerability? -✔✔Enforce encoding of special characters
✔✔Application credentials are stored in the database using simple hashes to store
passwords. An undiscovered credential recovery flaw allowed a security analyst to
download the database and expose passwords using their GPU to crack the simple
encryption. How should the organization remediate this vulnerability? -✔✔Enforce the
use of strong, salted hashing functions when storing passwords
✔✔During functional testing, a QA analyst using a non-admin account caused an
application exception. After the exception was handled, the tester was able to navigate
to the admin section of the application by typing the URL directly into the browser
address bar. They were unable to force the same navigation before the exception was
thrown. How should the organization remediate this vulnerability? -✔✔Ensure user
privileges are restored to the appropriate level after exceptions
✔✔The product security incident response team (PSIRT) determined a reported
vulnerability was credible and of a high enough severity that it needs to be fixed. What
is the response team's next step? -✔✔Identify resources and schedule the fix
✔✔Organizational leadership is considering buying a competitor and has asked the
software security team to develop a plan to ensure the competitor's point-of-sale system
, complies with organizational policies. Which post-release deliverable is being
described? -✔✔Security strategy for M&A products
✔✔The software security team has been tasked with identifying who will be involved
when security vulnerabilities are reported from external entities. They are creating a
RACI matrix that will identify stakeholders by who is responsible, accountable,
consulted, and informed of any new vulnerabilities. Which post-release deliverable is
being described? -✔✔External vulnerability disclosure response process
✔✔After determining a reported vulnerability was a credible claim, the product security
incident response team (PSIRT) worked with development teams to create and test a
patch. The patch is scheduled to be released at the end of the month.What is the
response team's next step? -✔✔Notify customers that the fix is available
✔✔The organization is moving from a waterfall to an agile software development
methodology, so the software security group must adapt the security development life
cycle as well. They have decided to break out security requirements and deliverables to
fit better in the iterative life cycle by defining every-sprint requirements, one-time
requirements, bucket requirements, and final security review requirements. Which type
of requirement states that all user input values must be validated by type, size, and
range? -✔✔Every-sprint requirement
✔✔The software security group is conducting a maturity assessment using the Building
Security in Maturity Model (BSIMM). They are currently focused on reviewing security
testing results from recently completed initiatives.Which BSIMM domain is being
assessed? -✔✔Software security development life cycle (SSDL) touchpoints
✔✔The organization is moving from a waterfall to an agile software development
methodology, so the software security group must adapt the security development life
cycle as well. They have decided to break out security requirements and deliverables to
fit better in the iterative life cycle by defining every-sprint requirements, one-time
requirements, bucket requirements, and final security review requirements. Which type
of requirement states that the team must perform remote procedure call (RPC) fuzz
testing? -✔✔Bucket requirement
✔✔ What is a study of real-world software security initiatives organized so companies
can measure their initiatives and understand how to evolve them over time?, -
✔✔Building Security In Maturity Model (BSIMM)
✔✔What is the analysis of computer software that is performed without executing
programs? -✔✔Static analysis
✔✔Which International Organization for Standardization (ISO) standard is the
benchmark for information security today? -✔✔ISO/IEC 27001.