Escrito por estudiantes que aprobaron Inmediatamente disponible después del pago Leer en línea o como PDF ¿Documento equivocado? Cámbialo gratis 4,6 TrustPilot
logo-home
Document preview thumbnail
Vista previa 4 fuera de 120 páginas
Examen

WGU MASTER'S COURSE C706 TEST BANK SECURE SOFTWARE DESIGN EXAM LATEST 2024 ACTUAL EXAM 400 QUESTIONS AND CORRECT DETAILED ANSWERS WITH RATIONALES (VERIFIED ANSWERS) |ALREADY GRADED A+ |

Document preview thumbnail
Vista previa 4 fuera de 120 páginas

WGU MASTER'S COURSE C706 TEST BANK SECURE SOFTWARE DESIGN EXAM LATEST 2024 ACTUAL EXAM 400 QUESTIONS AND CORRECT DETAILED ANSWERS WITH RATIONALES (VERIFIED ANSWERS) |ALREADY GRADED A+ |

Vista previa del contenido

WGU MASTER\\\'S COURSE C706 TEST BANK SECURE SOFTWARE DESIGN EXAM LATEST 2024

ACTUAL EXAM 400 QUESTIONS AND CORRECT

DETAILED ANSWERS WITH RATIONALES (VERIFIED ANSWERS) |ALREADY GRADED A+ |

Explain the Generic Risk Model.

The General Risk Model is a more subjective model that uses the formula "Risk = Likelihood x Impact" to
represent a threat mathematically.

i. With the General Risk Model, likelihood is defined by the ease of exploitation and the possibility
of realizing a threat.

ii. Impact is defined by the damage potential and the extent of the impact




Explain the TRIKE Model.

TRIKE is a unique, open-source threat modeling process focused on satisfying the security auditing
process from a cyber risk management perspective. The foundation of the Trike threat modeling
methodology is a "requirements model." The requirements model ensures the assigned level of risk for
each asset is "acceptable" to the various stakeholders.




How do you mitigate STRIDE spoofing and what security principle does it affect?

Authentication. Implement secure user authentication methods, including both secure password
requirements and multi-factor authentication (MFA).




How do you mitigate STRIDE Tampering and what security principle does it affect?

Integrity. The application should be designed to validate user inputs, and encode outputs. Static code
analysis should be used to identify vulnerabilities to tampering in the application both during the
development stage and once the application is in production.




How do you mitigate STRIDE Repudiation and what security principle does it affect?

Non-Repudiation. incorporating digital signatures in the application that provide proof of actions, or
ensuring that full, tamper-proof logs are in place.

,How do you mitigate STRIDE Info Disclosure and what security principle does it affect?

Confidentiality. Error messages, response headers, and background information should be as generic as
possible to avoid revealing clues about the application's behavior.

Proper access controls and authorizations should be in place to prevent unauthorized access to
information. The application itself should be checked over from a user perspective to validate that
developer comments and other information are not revealed in the production environment.




How do you mitigate STRIDE Denial of Service and what security principle does it affect?

Availability. Configuring firewalls to block traffic from certain sources such as reserved, loopback, or
private IP addresses, or unassigned DCHPDHCP clients, or introducing rate limiting to manage traffic




How do you mitigate STRIDE Elevation of Privilege and what security principle does it affect?

Authorization. includes managing the identity lifecycle, enforcing the principle of least privilege for all
users, hardening systems and applications through configuration changes, removing unnecessary rights
and access, closing ports




What are some common defects software testing should look for?

a. XSS

b. SQL Injection

c. Errors with applications

d. Patch errors

e. Buffer overflow

f. Memory leaks

g. Assertion failures

h. Error handling

,What types of tools are these?

a. AppScan by IBM

b. GFI Languard by GFI

c. Hailstorm by Cenzic

d. McAfee Vulnerability Manager (MVM) by McAfee

e. Nessus by Tenable Network Security

f. Retina Web Security Scanner by eEye Digital Security

g. WebInspect by HP

Vulnerability Scanning Tools




What are the OWASP security design principles?

a. Defense in depth (complete mediation)

b. Use a positive security model: Fail-safe defaults, minimize attack surface



Stuvia.co.uk - The Marketplace for Revision Notes & Study Guides

WGU MASTER'S COURSE C706 -

DESIGN EXAM LATEST 2024 ACTUAL EXAM 400 QUESTIONS

AND CORRECT DETAILED ANSWERS WITH RATIONALES

(VERIFIED ANSWERS) |ALREADY GRADED A+



c. Fail securely.

d. Run with least privilege.

e. Avoid security by obscurity (open design).

f. Keep security simple (verifiable, economy of mechanism).

g. Detect intrusions (compromise recording).

h. Don't trust infrastructure. Don't trust services.

i. Establish secure defaults

, What is code review and its four basic types?

Allows you to find and fix many security issues before the code is tested or shipped. There are four basic
techniques for analyzing the security of a software application:

1. automated scanning

2. manual penetration testing

3. static analysis

4. manual code review






www.stuvia.com

Stuvia.co.uk - The Marketplace for Revision Notes & Study Guides

WGU MASTER'S COURSE C706 -

DESIGN EXAM LATEST 2024 ACTUAL EXAM 400 QUESTIONS

AND CORRECT DETAILED ANSWERS WITH RATIONALES

(VERIFIED ANSWERS) |ALREADY GRADED A+




What is a step for constructing a threat model for a project when using practical risk analysis?



A Align your business goals

B Apply engineering methods

C Estimate probability of project time

D Make a list of what you are trying to protect - ANSWER-D



Which cyber threats are typically surgical by nature, have highly specific targeting, and are
technologically sophisticated?

Información del documento

Subido en
22 de octubre de 2024
Número de páginas
120
Escrito en
2024/2025
Tipo
Examen
Contiene
Preguntas y respuestas
$28.49

¿Documento equivocado? Cámbialo gratis Dentro de los 14 días posteriores a la compra y antes de descargarlo, puedes elegir otro documento. Puedes gastar el importe de nuevo.
Escrito por estudiantes que aprobaron
Inmediatamente disponible después del pago
Leer en línea o como PDF

Seller avatar
Los indicadores de reputación están sujetos a la cantidad de artículos vendidos por una tarifa y las reseñas que ha recibido por esos documentos. Hay tres niveles: Bronce, Plata y Oro. Cuanto mayor reputación, más podrás confiar en la calidad del trabajo del vendedor.
Creativepdf
3.8
(5)
Vendido
38
Seguidores
28
Artículos
2597
Última venta
5 meses hace


Por qué los estudiantes eligen Stuvia

Creado por compañeros estudiantes, verificado por reseñas

Calidad en la que puedes confiar: escrito por estudiantes que aprobaron y evaluado por otros que han usado estos resúmenes.

¿No estás satisfecho? Elige otro documento

¡No te preocupes! Puedes elegir directamente otro documento que se ajuste mejor a lo que buscas.

Paga como quieras, empieza a estudiar al instante

Sin suscripción, sin compromisos. Paga como estés acostumbrado con tarjeta de crédito y descarga tu documento PDF inmediatamente.

Student with book image

“Comprado, descargado y aprobado. Así de fácil puede ser.”

Alisha Student

Preguntas frecuentes