Assessment 2026 | Questions & Answers with
Rationales | Complete Study Guide | Latest
Update | Instant Download
Section 1: Foundational Security Concepts and Design Principles (Questions 1–30)
Question 1
What is the primary goal of secure software design?
A. Maximize software performance
B. Protect applications from security threats
C. Reduce development time
D. Enhance user interface
Correct Answer: B
Rationale: Secure design focuses on mitigating vulnerabilities throughout the SDLC. The
primary goal is to protect applications from security threats by building security into the
product from the earliest stages of development .
,Question 2
Which SDLC phase is most critical for integrating security?
A. Testing
B. Requirements gathering
C. Deployment
D. Maintenance
Correct Answer: B
Rationale: Early integration in requirements ensures security is built-in, per NIST guidelines.
Defining security requirements during the requirements phase ensures security drives
design, implementation, and verification rather than being bolted on later .
Question 3
What is the purpose of threat modeling in secure software design?
A. Optimize code efficiency
B. Identify potential security risks
C. Increase system uptime
D. Reduce hardware costs
Correct Answer: B
Rationale: Threat modeling, as per OWASP, maps risks to mitigate them proactively. It is a
structured process for identifying potential security risks before software is deployed .
,Question 4
The principle of least privilege means that:
A. Users should have full access to all systems
B. Users should have the minimum level of access necessary to perform their functions
C. Users should have no access to any systems
D. Users should share administrative accounts
Correct Answer: B
Rationale: The principle of least privilege grants users the minimum access necessary to
perform their functions. Each microservice should have a dedicated account with only
necessary permissions .
Question 5
Which security principle advocates for using multiple layers of security controls to protect
assets?
A. Security through Obscurity
B. Defense in Depth
C. Single Point of Failure
D. Fail-Open
Correct Answer: B
, Rationale: Defense in Depth involves layering security controls so that if one fails, others
are in place to stop an attack. Firewalls, IDS, encryption, access controls, and training
together represent this strategy .
Question 6
A system is designed to default to a secure state if an error or exception occurs. This is an
example of:
A. Fail-Open
B. Fail-Safe (Fail-Secure)
C. Economy of Mechanism
D. Open Design
Correct Answer: B
Rationale: Fail-safe (or fail-secure) design ensures that if a system fails, it defaults to a
secure state (e.g., a firewall blocking all traffic if it crashes). Fail-open would allow traffic
through upon failure, which is insecure .
Question 7
The "Economy of Mechanism" principle in secure design states that:
A. Security mechanisms should be as complex as possible
B. Security mechanisms should be simple and small