WGUMASTER'SCOURSEC706-SECURESOFTWARE
DESIGNEXAMLATEST2024ACTUALEXAM400QUESTIONSA
NDCORRECTDETAILEDANSWERS WITHRATIONALES(VERIF I z z z z
EDANSWERS)|ALREADYGRADEDA+ z z
Whatziszazstepzforzconstructingzazthreatzmodelzforzazprojectzwhenzusingzpracticalzriskzanalysis?
AzAlignzyourzbusinesszgoals
BzApplyzengineeringzmethods
CzEstimatezprobabilityzofzprojectztime
DzMakezazlistzofzwhatzyouzareztryingztozprotectz-z ANSWER-D
Whichzcyberzthreatszareztypicallyzsurgicalzbyznature,zhavezhighlyzspecificztargeting,zandzareztechnologicalzl
yzsophisticated?
AzTacticalzattacks
BzCriminalzattacks
CzStrategiczattacks
DzUser-specificzattacksz-zANSWER-A
Whichztypezofzcyberattackszarezoftenzintendedztozelevatezawarenesszofzaztopic?
AzCyberwarfare
BzTacticalzattacks
CzUser-specificzattacks
DzSociopoliticalzattacksz-z ANSWER-D
Whatztypezofzattackzlockszazuser'szdesktopzandzthenzrequireszazpaymentztozunlockzit?
AzPhishing
, WGUMASTER'SCOURSEC706-SECURESOFTWARE
DESIGNEXAMLATEST2024ACTUALEXAM400QUESTIONSA
NDCORRECTDETAILEDANSWERS WITHRATIONALES(VERIF I z z z z
EDANSWERS)|ALREADYGRADEDA+ z z
BzKeylogger
CzRansomware
DzDenial-of-servicez-zANSWER-C
WhatziszazcountermeasurezagainstzvariouszformszofzXMLzandzXMLzpathzinjectionzattacks?
AzXMLznamezwrapping
BzXMLzunicodezencoding
CzXMLzattributezescaping
DzXMLzdistinguishedznamezescapingz-zANSWER-C
WhichzcountermeasureziszusedztozmitigatezSQLzinjectionzattacks?
AzSQLzFirewall
BzProjectedzbijection
CzQueryzparameterization
DzProgressivezColdFusionz-zANSWER-C
Whatziszanzappropriatezcountermeasureztozanzescalationzofzprivilegezattack?
AzEnforcingzstrongzpasswordzpolicies
BzUsingzstandardzencryptionzalgorithmszandzcorrectzkeyzsizes
CzEnablingzthezauditingzandzloggingzofzallzadministrationzactivities
DzRestrictingzaccessztozspecificzoperationszthroughzrole-basedzaccesszcontrolsz-zANSWER-D
, WGUMASTER'SCOURSEC706-SECURESOFTWARE
DESIGNEXAMLATEST2024ACTUALEXAM400QUESTIONSA
NDCORRECTDETAILEDANSWERS WITHRATIONALES(VERIF I z z z z
EDANSWERS)|ALREADYGRADEDA+ z z
Whichconfigurationzmanagementzsecurityzcountermeasurezimplementszleastzprivilegezaccesszcontrol?
AzFollowingzstrongzpasswordzpoliciesztozrestrictzaccess
BzRestrictingzfilezaccessztozuserszbasedzonzauthorization
CzAvoidingzclearztextzformatzforzcredentialszandzsensitivezdata
DzUsingzAESz256zencryptionzforzcommunicationszofzazsensitiveznaturez-zANSWER-B
Whichzphasezofzthezsoftwarezdevelopmentzlifezcyclez(SDL/SDLC)zwouldzbezusedztozdeterminezthezminiz
mumzsetzofzprivilegeszrequiredztozperformztheztargetedztaskzandzrestrictzthezuserztozazdomainzwithzthoszez
privileges?
AzDesign
BzDeploy
CzDevelopment
DzImplementationz-zANSWER-A
Whichzleastzprivilegezmethodziszmorezgranularzinzscopezandzgrantszspecificzprocesseszonlyzthezprivilegezsz
necessaryztozperformzcertainzrequiredzfunctions,zinsteadzofzgrantingzthemzunrestrictedzaccessztozthezszyst
em?
AzEntitlementzprivilege
BzSeparationzofzprivilege
CzAggregationzofzprivileges
DzSegregationzofzresponsibilitiesz-zANSWER-B
Whyzdoeszprivilegezcreepzposezazpotentialzsecurityzrisk?
, WGUMASTER'SCOURSEC706-SECURESOFTWARE
DESIGNEXAMLATEST2024ACTUALEXAM400QUESTIONSA
NDCORRECTDETAILEDANSWERS WITHRATIONALES(VERIF I z z z z
EDANSWERS)|ALREADYGRADEDA+ z z
AzUserzprivilegeszdoznotzmatchztheirzjobzrole.
BzWithzmorezprivileges,ztherezarezmorezresponsibilities.
CzAuditingzwillzshowzazmismatchzbetweenzindividualzresponsibilitieszandztheirzaccesszrights.
DzUserszhavezmorezprivilegeszthanztheyzneedzandzmayzperformzactionszoutsideztheirzjobzdescription.z-
ANSWER-D
Azsystemzdeveloperziszimplementingzaznewzsaleszsystem.zThezsystemzdeveloperziszconcernedzthatzunautzhorize
dzindividualszmayzbezableztozviewzsensitivezcustomerzfinancialzdata.
Whichzfamilyzofznonfunctionalzrequirementszshouldzbezconsideredzaszpartzofzthezacceptancezcriteria?
AzIntegrity
BzAvailability
CzNonrepudition
DzConfidentialityz-zANSWER-D
Azprojectzmanagerziszgivenztheztaskztozcomezupzwithznonfunctionalzacceptancezcriteriazrequirementszfozrz
businesszownerszaszpartzofzazprojectzdelivery.
Whichznonfunctionalzrequirementzshouldzbezappliedztozthezacceptancezcriteria?
AzGivezsearchzoptionsztozusers
BzEvaluateztestzexecutionzresults
CzDividezuserszintozgroupszandzgivezthemzseparatezrights
DzDevelopzsoftwarezthatzkeepszdownwardzcompatibilityzintactz-zANSWER-B
DESIGNEXAMLATEST2024ACTUALEXAM400QUESTIONSA
NDCORRECTDETAILEDANSWERS WITHRATIONALES(VERIF I z z z z
EDANSWERS)|ALREADYGRADEDA+ z z
Whatziszazstepzforzconstructingzazthreatzmodelzforzazprojectzwhenzusingzpracticalzriskzanalysis?
AzAlignzyourzbusinesszgoals
BzApplyzengineeringzmethods
CzEstimatezprobabilityzofzprojectztime
DzMakezazlistzofzwhatzyouzareztryingztozprotectz-z ANSWER-D
Whichzcyberzthreatszareztypicallyzsurgicalzbyznature,zhavezhighlyzspecificztargeting,zandzareztechnologicalzl
yzsophisticated?
AzTacticalzattacks
BzCriminalzattacks
CzStrategiczattacks
DzUser-specificzattacksz-zANSWER-A
Whichztypezofzcyberattackszarezoftenzintendedztozelevatezawarenesszofzaztopic?
AzCyberwarfare
BzTacticalzattacks
CzUser-specificzattacks
DzSociopoliticalzattacksz-z ANSWER-D
Whatztypezofzattackzlockszazuser'szdesktopzandzthenzrequireszazpaymentztozunlockzit?
AzPhishing
, WGUMASTER'SCOURSEC706-SECURESOFTWARE
DESIGNEXAMLATEST2024ACTUALEXAM400QUESTIONSA
NDCORRECTDETAILEDANSWERS WITHRATIONALES(VERIF I z z z z
EDANSWERS)|ALREADYGRADEDA+ z z
BzKeylogger
CzRansomware
DzDenial-of-servicez-zANSWER-C
WhatziszazcountermeasurezagainstzvariouszformszofzXMLzandzXMLzpathzinjectionzattacks?
AzXMLznamezwrapping
BzXMLzunicodezencoding
CzXMLzattributezescaping
DzXMLzdistinguishedznamezescapingz-zANSWER-C
WhichzcountermeasureziszusedztozmitigatezSQLzinjectionzattacks?
AzSQLzFirewall
BzProjectedzbijection
CzQueryzparameterization
DzProgressivezColdFusionz-zANSWER-C
Whatziszanzappropriatezcountermeasureztozanzescalationzofzprivilegezattack?
AzEnforcingzstrongzpasswordzpolicies
BzUsingzstandardzencryptionzalgorithmszandzcorrectzkeyzsizes
CzEnablingzthezauditingzandzloggingzofzallzadministrationzactivities
DzRestrictingzaccessztozspecificzoperationszthroughzrole-basedzaccesszcontrolsz-zANSWER-D
, WGUMASTER'SCOURSEC706-SECURESOFTWARE
DESIGNEXAMLATEST2024ACTUALEXAM400QUESTIONSA
NDCORRECTDETAILEDANSWERS WITHRATIONALES(VERIF I z z z z
EDANSWERS)|ALREADYGRADEDA+ z z
Whichconfigurationzmanagementzsecurityzcountermeasurezimplementszleastzprivilegezaccesszcontrol?
AzFollowingzstrongzpasswordzpoliciesztozrestrictzaccess
BzRestrictingzfilezaccessztozuserszbasedzonzauthorization
CzAvoidingzclearztextzformatzforzcredentialszandzsensitivezdata
DzUsingzAESz256zencryptionzforzcommunicationszofzazsensitiveznaturez-zANSWER-B
Whichzphasezofzthezsoftwarezdevelopmentzlifezcyclez(SDL/SDLC)zwouldzbezusedztozdeterminezthezminiz
mumzsetzofzprivilegeszrequiredztozperformztheztargetedztaskzandzrestrictzthezuserztozazdomainzwithzthoszez
privileges?
AzDesign
BzDeploy
CzDevelopment
DzImplementationz-zANSWER-A
Whichzleastzprivilegezmethodziszmorezgranularzinzscopezandzgrantszspecificzprocesseszonlyzthezprivilegezsz
necessaryztozperformzcertainzrequiredzfunctions,zinsteadzofzgrantingzthemzunrestrictedzaccessztozthezszyst
em?
AzEntitlementzprivilege
BzSeparationzofzprivilege
CzAggregationzofzprivileges
DzSegregationzofzresponsibilitiesz-zANSWER-B
Whyzdoeszprivilegezcreepzposezazpotentialzsecurityzrisk?
, WGUMASTER'SCOURSEC706-SECURESOFTWARE
DESIGNEXAMLATEST2024ACTUALEXAM400QUESTIONSA
NDCORRECTDETAILEDANSWERS WITHRATIONALES(VERIF I z z z z
EDANSWERS)|ALREADYGRADEDA+ z z
AzUserzprivilegeszdoznotzmatchztheirzjobzrole.
BzWithzmorezprivileges,ztherezarezmorezresponsibilities.
CzAuditingzwillzshowzazmismatchzbetweenzindividualzresponsibilitieszandztheirzaccesszrights.
DzUserszhavezmorezprivilegeszthanztheyzneedzandzmayzperformzactionszoutsideztheirzjobzdescription.z-
ANSWER-D
Azsystemzdeveloperziszimplementingzaznewzsaleszsystem.zThezsystemzdeveloperziszconcernedzthatzunautzhorize
dzindividualszmayzbezableztozviewzsensitivezcustomerzfinancialzdata.
Whichzfamilyzofznonfunctionalzrequirementszshouldzbezconsideredzaszpartzofzthezacceptancezcriteria?
AzIntegrity
BzAvailability
CzNonrepudition
DzConfidentialityz-zANSWER-D
Azprojectzmanagerziszgivenztheztaskztozcomezupzwithznonfunctionalzacceptancezcriteriazrequirementszfozrz
businesszownerszaszpartzofzazprojectzdelivery.
Whichznonfunctionalzrequirementzshouldzbezappliedztozthezacceptancezcriteria?
AzGivezsearchzoptionsztozusers
BzEvaluateztestzexecutionzresults
CzDividezuserszintozgroupszandzgivezthemzseparatezrights
DzDevelopzsoftwarezthatzkeepszdownwardzcompatibilityzintactz-zANSWER-B