• ¿Documento equivocado? Cámbialo gratis
  • Escrito por estudiantes que aprobaron
  • Inmediatamente disponible después del pago
  • Leer en línea o como PDF
Vender
¿Dónde estudias?
Tu idioma
Document preview thumbnail
Vista previa 3 fuera de 25 páginas
Examen

WGU D385 V2 SOFTWARE SECURITY AND TESTING MASTER STUDY GUIDE EXAM

Document preview thumbnail
Vista previa 3 fuera de 25 páginas

WGU D385 V2 SOFTWARE SECURITY AND TESTING MASTER STUDY GUIDE EXAM

Vista previa del contenido

WGU D385 V2 SOFTWARE SECURITY
AND TESTING MASTER STUDY GUIDE
EXAM




1. When integrating security into the Software Development Life Cycle (SDLC), which

approach focuses on identifying security flaws early by moving testing to the initial stages of

development?

A. Shift-Right testing


B. Regression testing


C. Waterfall validation


D. Shift-Left testing


Answer: D


Conceptual Explanation: Shift-left testing emphasizes performing security activities as

early as possible in the development process to reduce remediation costs and complexity.


2. Which type of security testing tool is known for having a low false-positive rate because it

monitors an application’s execution and has access to its internal state?

A. SAST

,B. DAST


C. SCA


D. IAST


Answer: D


Conceptual Explanation: Interactive Application Security Testing (IAST) combines

elements of SAST and DAST, monitoring code execution to provide high accuracy.


3. To prevent SQL injection, which of the following is considered the most effective defense

mechanism?

A. Blacklisting common SQL keywords


B. Using parameterized queries and prepared statements


C. Client-side input validation


D. Escaping all single quotes in the input string


Answer: B


Conceptual Explanation: Parameterized queries ensure that the database treats user

input strictly as data, not executable code, effectively neutralizing injection attempts.


4. In the context of API security, what does the acronym BOLA stand for?

A. Broken Object Level Authorization


B. Binary Object Link Access

, C. Basic Online Login Authentication


D. Backend Operation Limit Alert


Answer: A


Conceptual Explanation: Broken Object Level Authorization (BOLA) occurs when an

application does not properly validate that a user has permission to access a specific object

ID.


5. Which Cross-Site Scripting (XSS) variant involves the malicious script being permanently

stored on the target server, such as in a database or comment field?

A. Reflected XSS


B. Stored XSS


C. DOM-based XSS


D. Blind XSS


Answer: B


Conceptual Explanation: Stored XSS occurs when a malicious script is saved on the server

and served to every user who views the affected page.


6. Which mechanism is used to prevent Cross-Site Request Forgery (CSRF) by ensuring that

the browser only sends cookies for requests originating from the same site?

A. HttpOnly attribute


B. Secure attribute

Información del documento

Subido en
31 de agosto de 2026
Número de páginas
25
Escrito en
2026/2027
Tipo
Examen
Contiene
Preguntas y respuestas
$15.99

¿Documento equivocado? Cámbialo gratis Dentro de los 14 días posteriores a la compra y antes de descargarlo, puedes elegir otro documento. Puedes gastar el importe de nuevo.
Escrito por estudiantes que aprobaron
Inmediatamente disponible después del pago
Leer en línea o como PDF

Seller avatar
Los indicadores de reputación están sujetos a la cantidad de artículos vendidos por una tarifa y las reseñas que ha recibido por esos documentos. Hay tres niveles: Bronce, Plata y Oro. Cuanto mayor reputación, más podrás confiar en la calidad del trabajo del vendedor.
Thebright
3.6
(44)
Vendido
247
Seguidores
6
Artículos
15205
Última venta
1 día hace




Por qué los estudiantes eligen Stuvia

Creado por compañeros estudiantes, verificado por reseñas

Calidad en la que puedes confiar: escrito por estudiantes que aprobaron y evaluado por otros que han usado estos resúmenes.

¿No estás satisfecho? Elige otro documento

¡No te preocupes! Puedes elegir directamente otro documento que se ajuste mejor a lo que buscas.

Paga como quieras, empieza a estudiar al instante

Sin suscripción, sin compromisos. Paga como estés acostumbrado con tarjeta de crédito y descarga tu documento PDF inmediatamente.

Student with book image

“Comprado, descargado y aprobado. Así de fácil puede ser.”

Alisha Student

Preguntas frecuentes