Escrito por estudiantes que aprobaron Inmediatamente disponible después del pago Leer en línea o como PDF ¿Documento equivocado? Cámbialo gratis 4,6 TrustPilot
logo-home
Document preview thumbnail
Vista previa 3 fuera de 16 páginas
Examen

WGU - D487

Document preview thumbnail
Vista previa 3 fuera de 16 páginas

WGU - D487 1. Privacy Compliance Report: The _________ report should provide progress against privacy requirements provided in earlier phases. Any outstanding requirement should be implemented as soon as possible. It is also prudent to assess any changes in laws/regulations to identify (and put on a roadmap) any new requirements. A4 D&D

Vista previa del contenido

WGU - D487
Study online at https://quizlet.com/_gpcp9p
1. Privacy Compliance Report: The _________ report should provide progress
against privacy requirements provided in earlier phases. Any outstanding require-
ment should be implemented as soon as possible. It is also prudent to assess any
changes in laws/regulations to identify (and put on a roadmap) any new require-
ments. A4 D&D
2. Security Testing Reports: A findings summary should be prepared for each
type of security testing: manual code review, static analysis, dynamic analysis,
penetration testing, and fuzzing. The reports should provide the type and number of
issues identified and any consistent theme that can be derived from the findings. A4
D&D
3. Remediation Report: A ____ report/dashboard should be prepared and updated
regularly from this stage. The purpose of this report is to showcase the security
posture and risk of the product at a technical level. A4 D&D
4. Security Assessment
What are the key activities in the Security Assessment phase of SDL?: SDL
Phase 1 (A1) = SDLC 1 Concept

Software security team is looped in early
Security team hosts a discovery meeting
Software security team discusses project plan
States what further work will be done
Privacy Impact Assessment (PIA) plan is created
5. Architecture
What are the key activities in the Architecture phase of SDL?: SDL Phase 2
(A2) = SDLC 2 Planning

A2 Policy compliance analysis
SDL policy assessment and scoping
Threat modeling & architecture security analysis
Open-source selection
Privacy information gathering and analysis
6. Design & Development
What are the key activities in the Design & Development phase of SDL?: SDL
Phase 3 (A3) = SDLC 3 Design & Development

A3 Policy compliance analysis
Security test plan composition
Static analysis updating



, WGU - D487
Study online at https://quizlet.com/_gpcp9p
Threat modeling analysis & review
Privacy implementation assessment
7. Design & Development Cont.
What are the key activities in the Design & Development Cont. phase of
SDL?: SDL Phase 4 (A4) = SDLC 4 Readiness

A4 Policy compliance analysis
Security test case execution
Static analysis
Fuzz testing
Privacy code review
Privacy validation and remediation
8. Ship
What are the key activities in the Ship phase of SDL?: SDL Phase 5 (A5) = SDLC
5 Release & Launch

A5 Policy compliance analysis
Vulnerability scan
Penetration testing
Open-source licensing review
Final privacy review
9. What is the purpose of the Product risk profile deliverable in Security
Assessment (A1)?: To estimate the actual cost of the product.
10. What is the goal of the SDL project outline in Security Assessment (A1)?-
: To map SDL activities to the development schedule.
11. Why are Applicable laws and regulations important in Security Assess-
ment (A1)?: To obtain formal sign-off from stakeholders on applicable laws.
12. What is the purpose of the Threat profile in Security Assessment (A1)?: To
guide SDL activities to mitigate threats.
13. What is the goal of the Certification requirements deliverable in Security
Assessment (A1)?: To list requirements for product and operations certifications.
14. Why is maintaining a List of third-party software important in Security
Assessment (A1)?: To identify dependence on third-party software.
15. What is the purpose of the Metrics template in Security Assessment (A1)?-
: To establish a cadence for regular reporting to executives.
16. What is the purpose of defining Business requirements in A2 Architec-
ture?: To establish software requirements, including Confidentiality, Integrity, and
Availability (CIA).



, WGU - D487
Study online at https://quizlet.com/_gpcp9p
17. What are Threat modeling artifacts used for in A2 Architecture?: They
include data flow diagrams, elements, and threat listings to assess security risks.
18. What is the goal of Architecture threat analysis in A2 Architecture?: To
prioritize threats and risks based on a detailed threat analysis.
19. What is a Risk mitigation plan in A2 Architecture?: A plan to mitigate, accept,
or tolerate risk within the system.
20. What does Policy compliance analysis ensure in A2 Architecture?: It en-
sures adherence to company policies and security regulations.
21. What is the purpose of Updated threat modeling artifacts in A3 Design &
Development?: To maintain data flow diagrams, elements, and threat listings for
security analysis.
22. What does a Design security review focus on in A3 Design & Develop-
ment?: It includes modifications to the design of software components based on
security assessments.
23. What is the purpose of Security test plans in A3 Design & Development?-
: To create a plan to mitigate, accept, or tolerate risk.
24. What does Updated policy compliance analysis ensure in A3 Design &
Development?: It ensures adherence to company policies.
25. What are Privacy implementation assessment results used for in A3 De-
sign & Development?: They provide recommendations from privacy assessments
to improve compliance.
26. What is the purpose of the Security test execution report in A4 Design &
Development?: To review progress against identified security test cases.
27. What does Updated policy compliance analysis ensure in A4 Design &
Development?: It ensures adherence to company policies.
28. What is the Privacy compliance report used for in A4 Design & Develop-
ment?: To validate that recommendations from the privacy assessment have been
implemented.
29. What are Security testing reports used for in A4 Design & Development?-
: They document findings from different types of security testing.
30. What is the Remediation report used for in A4 Design & Development?: To
provide the status of the security posture of the product.
31. What does Updated policy compliance analysis ensure in A5 Ship?: It
ensures adherence to company policies.
32. What are Security testing reports used for in A5 Ship?: They document
findings from different types of security testing in this phase of the SDL.
33. What is the purpose of the Remediation report in A5 Ship?: To provide the
status of the security posture of the product.

Información del documento

Subido en
20 de marzo de 2025
Número de páginas
16
Escrito en
2024/2025
Tipo
Examen
Contiene
Preguntas y respuestas
$24.99

¿Documento equivocado? Cámbialo gratis Dentro de los 14 días posteriores a la compra y antes de descargarlo, puedes elegir otro documento. Puedes gastar el importe de nuevo.
Escrito por estudiantes que aprobaron
Inmediatamente disponible después del pago
Leer en línea o como PDF

Seller avatar
Los indicadores de reputación están sujetos a la cantidad de artículos vendidos por una tarifa y las reseñas que ha recibido por esos documentos. Hay tres niveles: Bronce, Plata y Oro. Cuanto mayor reputación, más podrás confiar en la calidad del trabajo del vendedor.
Creativepdf
3.8
(5)
Vendido
38
Seguidores
28
Artículos
2597
Última venta
5 meses hace


Por qué los estudiantes eligen Stuvia

Creado por compañeros estudiantes, verificado por reseñas

Calidad en la que puedes confiar: escrito por estudiantes que aprobaron y evaluado por otros que han usado estos resúmenes.

¿No estás satisfecho? Elige otro documento

¡No te preocupes! Puedes elegir directamente otro documento que se ajuste mejor a lo que buscas.

Paga como quieras, empieza a estudiar al instante

Sin suscripción, sin compromisos. Paga como estés acostumbrado con tarjeta de crédito y descarga tu documento PDF inmediatamente.

Student with book image

“Comprado, descargado y aprobado. Así de fácil puede ser.”

Alisha Student

Preguntas frecuentes