• ¿Documento equivocado? Cámbialo gratis
  • Escrito por estudiantes que aprobaron
  • Inmediatamente disponible después del pago
  • Leer en línea o como PDF
Vender
¿Dónde estudias?
Tu idioma
Document preview thumbnail
Vista previa 3 fuera de 24 páginas
Examen

WGU D385 V2 SOFTWARE SECURITY AND TESTING MASTER EXAM STUDY GUIDE

Document preview thumbnail
Vista previa 3 fuera de 24 páginas

WGU D385 V2 SOFTWARE SECURITY AND TESTING MASTER EXAM STUDY GUIDE

Vista previa del contenido

WGU D385 V2 SOFTWARE SECURITY
AND TESTING MASTER EXAM STUDY
GUIDE




1. Which phase of the Software Development Life Cycle (SDLC) is most cost-effective for

identifying and mitigating security flaws?

A. Requirements Analysis


B. Production


C. Testing


D. Deployment


Answer: A


Conceptual Explanation: Identifying security requirements early in the SDLC

(Requirements Analysis) prevents costly rework in later stages.


2. In the context of input validation, which approach is generally considered more secure?

A. Blacklisting known bad characters


B. Relying on client-side validation only


C. Sanitizing inputs using regular expressions after processing

,D. Whitelisting known good patterns


Answer: D


Conceptual Explanation: Whitelisting is more secure because it only allows known good

input, whereas blacklisting often fails to account for new or creative attack vectors.


3. Which technique is the most effective primary defense against SQL Injection?

A. Using stored procedures without parameters


B. Using Prepared Statements (with Parameterized Queries)


C. Implementing Web Application Firewalls (WAF)


D. Escaping all single quotes in user input


Answer: B


Conceptual Explanation: Prepared statements ensure that the database treats user input

as data, not executable code, effectively neutralizing SQL injection.


4. A security analyst is using a tool that analyzes the source code of an application without

executing it. What is this type of testing called?

A. DAST


B. Penetration Testing


C. SAST


D. Fuzzing

, Answer: C


Conceptual Explanation: Static Application Security Testing (SAST) examines the code or

binaries without executing the application.


5. What is the primary purpose of Cross-Origin Resource Sharing (CORS)?

A. To prevent Cross-Site Scripting (XSS)


B. To encrypt data transmitted between the client and server


C. To allow a web page to make requests to a different domain than the one that served it


D. To store session tokens securely in the browser


Answer: C


Conceptual Explanation: CORS is a mechanism that uses additional HTTP headers to tell

browsers to give a web application running at one origin access to selected resources from

a different origin.


6. Which OWASP Top 10 category involves an attacker exploiting a reference to an internal

implementation object, such as a file or database key?

A. Broken Access Control


B. Cryptographic Failures


C. Injection


D. Security Misconfiguration


Answer: A

Información del documento

Subido en
31 de agosto de 2026
Número de páginas
24
Escrito en
2026/2027
Tipo
Examen
Contiene
Preguntas y respuestas
$15.99

¿Documento equivocado? Cámbialo gratis Dentro de los 14 días posteriores a la compra y antes de descargarlo, puedes elegir otro documento. Puedes gastar el importe de nuevo.
Escrito por estudiantes que aprobaron
Inmediatamente disponible después del pago
Leer en línea o como PDF

Seller avatar
Los indicadores de reputación están sujetos a la cantidad de artículos vendidos por una tarifa y las reseñas que ha recibido por esos documentos. Hay tres niveles: Bronce, Plata y Oro. Cuanto mayor reputación, más podrás confiar en la calidad del trabajo del vendedor.
Thebright
3.6
(44)
Vendido
247
Seguidores
6
Artículos
15205
Última venta
1 día hace




Por qué los estudiantes eligen Stuvia

Creado por compañeros estudiantes, verificado por reseñas

Calidad en la que puedes confiar: escrito por estudiantes que aprobaron y evaluado por otros que han usado estos resúmenes.

¿No estás satisfecho? Elige otro documento

¡No te preocupes! Puedes elegir directamente otro documento que se ajuste mejor a lo que buscas.

Paga como quieras, empieza a estudiar al instante

Sin suscripción, sin compromisos. Paga como estés acostumbrado con tarjeta de crédito y descarga tu documento PDF inmediatamente.

Student with book image

“Comprado, descargado y aprobado. Así de fácil puede ser.”

Alisha Student

Preguntas frecuentes