WGU D487 SECURE SW DESIGN OA
EXAM 2025 ACTUAL EXAM
COMPLETE ACCURATE EXAM
QUESTIONS WITH 100% DETAILED
VERIFIED AND CORRECT ANSWERS
ACTUAL BRAND-NEW EXAM
ALREADY GRADED A+
Which of the following best describes the role of
compliance requirements in secure software
development?
A) Compliance requirements are optional and may be
disregarded to reduce project scope
B) Compliance requirements ensure the software meets
industry and legal standards, protecting both the
organization and users
C) Compliance requirements are only relevant in the
testing phase
1
,D) Compliance requirements are used solely for
auditing and not necessary for development
B) Compliance requirements ensure the software meets
industry and legal standards, protecting both the
organization and users
A project team is developing software that processes
sensitive customer information. To secure this data, the
team decides to categorize it based on sensitivity levels.
Why is this categorization essential in data protection?
A) It allows the team to ignore security requirements for
low-sensitivity data
B) It enables the team to apply appropriate security
controls based on data sensitivity, ensuring high- risk
data is more protected
C) It removes the need for data access controls
D) It minimizes the importance of encrypting
sensitive data
B) It enables the team to apply appropriate security
controls based on data sensitivity, ensuring high- risk
data is more protected
As part of a data protection strategy, a security analyst
suggests classifying data to determine ownership and
access levels. Why is identifying data ownership
important?
2
,A) It allows only the development team to access data
B) It clarifies accountability for data security and
helps set permissions based on data ownership
C) It eliminates the need to monitor data access logs
D) It restricts data handling to a single user
B) It clarifies accountability for data security and helps
set permissions based on data ownership
The development team is required to implement data
protection for both structured and unstructured data. What
is one critical reason for protecting unstructured data,
such as documents or emails?
A) Unstructured data is less valuable, so protection is
optional
B) Unstructured data often contains sensitive
information that, if exposed, could lead to security
breaches
C) Structured data alone requires protection for
regulatory compliance
D) Data protection applies only to structured formats
B) Unstructured data often contains sensitive
information that, if exposed, could lead to security
breaches
A software application requires access controls to limit
data access to authorized users. What is the primary
purpose of implementing access controls as
part of data protection?
3
, A) To simplify the data access process for all users
B) To restrict data access to individuals based on their
role and need, ensuring sensitive data remains protected
C) To allow unrestricted data access for internal
users
D) To ensure that all users have equal access to data
B) To restrict data access to individuals based on their
role and need, ensuring sensitive data remains protected
As part of data protection efforts, the team is tasked with
establishing guidelines for sensitive data. Which
guideline is most critical for protecting sensitive data?
A) Limiting all users from accessing data
B) Encrypting sensitive data to prevent unauthorized
access
C) Allowing sensitive data to be shared freely within the
organization
D) Storing all sensitive data in plaintext for easy
access
B) Encrypting sensitive data to prevent unauthorized
access
Anna is responsible for uncovering security requirements
for a new software project. Which of the following
approaches would best support effective security
requirement discovery?
4
EXAM 2025 ACTUAL EXAM
COMPLETE ACCURATE EXAM
QUESTIONS WITH 100% DETAILED
VERIFIED AND CORRECT ANSWERS
ACTUAL BRAND-NEW EXAM
ALREADY GRADED A+
Which of the following best describes the role of
compliance requirements in secure software
development?
A) Compliance requirements are optional and may be
disregarded to reduce project scope
B) Compliance requirements ensure the software meets
industry and legal standards, protecting both the
organization and users
C) Compliance requirements are only relevant in the
testing phase
1
,D) Compliance requirements are used solely for
auditing and not necessary for development
B) Compliance requirements ensure the software meets
industry and legal standards, protecting both the
organization and users
A project team is developing software that processes
sensitive customer information. To secure this data, the
team decides to categorize it based on sensitivity levels.
Why is this categorization essential in data protection?
A) It allows the team to ignore security requirements for
low-sensitivity data
B) It enables the team to apply appropriate security
controls based on data sensitivity, ensuring high- risk
data is more protected
C) It removes the need for data access controls
D) It minimizes the importance of encrypting
sensitive data
B) It enables the team to apply appropriate security
controls based on data sensitivity, ensuring high- risk
data is more protected
As part of a data protection strategy, a security analyst
suggests classifying data to determine ownership and
access levels. Why is identifying data ownership
important?
2
,A) It allows only the development team to access data
B) It clarifies accountability for data security and
helps set permissions based on data ownership
C) It eliminates the need to monitor data access logs
D) It restricts data handling to a single user
B) It clarifies accountability for data security and helps
set permissions based on data ownership
The development team is required to implement data
protection for both structured and unstructured data. What
is one critical reason for protecting unstructured data,
such as documents or emails?
A) Unstructured data is less valuable, so protection is
optional
B) Unstructured data often contains sensitive
information that, if exposed, could lead to security
breaches
C) Structured data alone requires protection for
regulatory compliance
D) Data protection applies only to structured formats
B) Unstructured data often contains sensitive
information that, if exposed, could lead to security
breaches
A software application requires access controls to limit
data access to authorized users. What is the primary
purpose of implementing access controls as
part of data protection?
3
, A) To simplify the data access process for all users
B) To restrict data access to individuals based on their
role and need, ensuring sensitive data remains protected
C) To allow unrestricted data access for internal
users
D) To ensure that all users have equal access to data
B) To restrict data access to individuals based on their
role and need, ensuring sensitive data remains protected
As part of data protection efforts, the team is tasked with
establishing guidelines for sensitive data. Which
guideline is most critical for protecting sensitive data?
A) Limiting all users from accessing data
B) Encrypting sensitive data to prevent unauthorized
access
C) Allowing sensitive data to be shared freely within the
organization
D) Storing all sensitive data in plaintext for easy
access
B) Encrypting sensitive data to prevent unauthorized
access
Anna is responsible for uncovering security requirements
for a new software project. Which of the following
approaches would best support effective security
requirement discovery?
4