WGU D487 SECURE SW DESIGN OA
AND PRE ASSESSMENT EXAM 2025
ACTUAL EXAM COMPLETE
ACCURATE EXAM QUESTIONS WITH
100% DETAILED VERIFIED AND
CORRECT ANSWERS ACTUAL
BRAND-NEW EXAM ALREADY
GRADED A+
WGU D487 OA
The organization is moving from a waterfall to an agile
software development methodology, so the software
security group must adapt the security development life
cycle as well. They have decided to break out security
requirements and deliverables to fit better in the iterative
life cycle by defining every- sprint requirements, one-
time requirements, bucket requirements, and final security
review requirements. Which type of requirement states
that all user input values must be validated by type, size,
and range?
-Every-sprint requirement
-Bucket requirement
-One-time requirement
-Final security review requirement -........... ANSWER...-
Every-sprint requirement
1
,The software security group is conducting a maturity
assessment using the Building Security in Maturity
Model (BSIMM). They are currently focused on
reviewing security testing results from recently
completed initiatives. Which BSIMM domain is being
assessed?
-Software security development life cycle (SSDL)
touchpoints
-Intelligence
-Governance
-Deployment - ....ANSWER...-Software security
development life cycle (SSDL) touchpoints
What is the study of real-world software security
initiatives organized so companies can measure their
initiatives and understand how to evolve them over time?
-Building Security in Maturity Model (BSIMM)
-Security features and design
-OWASP Software Assurance Maturity Model (SAMM)
-ISO 27001 - ....ANSWER...-Building Security in
Maturity Model (BSIMM)
What is the analysis of computer software that is
performed without executing programs?
2
,-static analysis
-fuzzing
-dynamic analysis
-owasp zap - ....ANSWER...-static analysis
what iso standard is the benchmark for information
security today?
-iso 27001
-iso 7799
-iso 27034
-iso 8601 - ....ANSWER...-iso 27001
what is the analysis of computer software that is
performed by executing programs on a real or virtual
processor in real time?
-dynamic analysis
-static analysis
-fuzzing
-security testing - ....ANSWER...-dynamic analysis
which person is responsible for designing, planning, and
implementing secure coding practices and security testing
methodologies?
-software security architect
3
, -product security developer
-software security champion
-software tester - ....ANSWER...-software security
architect
A potential threat was discovered during functional
testing of a file upload component when a QA analyst
was allowed to upload a shell script. Users should only
be allowed to upload image files. How should existing
security controls be adjusted to prevent this in the future?
-Validate all user input
-Enforce role-based authorization
-Ensure all data is encrypted in transit
-Force users to re-authenticate when accessing critical
functionality - ....ANSWER...-Validate all user input
4
AND PRE ASSESSMENT EXAM 2025
ACTUAL EXAM COMPLETE
ACCURATE EXAM QUESTIONS WITH
100% DETAILED VERIFIED AND
CORRECT ANSWERS ACTUAL
BRAND-NEW EXAM ALREADY
GRADED A+
WGU D487 OA
The organization is moving from a waterfall to an agile
software development methodology, so the software
security group must adapt the security development life
cycle as well. They have decided to break out security
requirements and deliverables to fit better in the iterative
life cycle by defining every- sprint requirements, one-
time requirements, bucket requirements, and final security
review requirements. Which type of requirement states
that all user input values must be validated by type, size,
and range?
-Every-sprint requirement
-Bucket requirement
-One-time requirement
-Final security review requirement -........... ANSWER...-
Every-sprint requirement
1
,The software security group is conducting a maturity
assessment using the Building Security in Maturity
Model (BSIMM). They are currently focused on
reviewing security testing results from recently
completed initiatives. Which BSIMM domain is being
assessed?
-Software security development life cycle (SSDL)
touchpoints
-Intelligence
-Governance
-Deployment - ....ANSWER...-Software security
development life cycle (SSDL) touchpoints
What is the study of real-world software security
initiatives organized so companies can measure their
initiatives and understand how to evolve them over time?
-Building Security in Maturity Model (BSIMM)
-Security features and design
-OWASP Software Assurance Maturity Model (SAMM)
-ISO 27001 - ....ANSWER...-Building Security in
Maturity Model (BSIMM)
What is the analysis of computer software that is
performed without executing programs?
2
,-static analysis
-fuzzing
-dynamic analysis
-owasp zap - ....ANSWER...-static analysis
what iso standard is the benchmark for information
security today?
-iso 27001
-iso 7799
-iso 27034
-iso 8601 - ....ANSWER...-iso 27001
what is the analysis of computer software that is
performed by executing programs on a real or virtual
processor in real time?
-dynamic analysis
-static analysis
-fuzzing
-security testing - ....ANSWER...-dynamic analysis
which person is responsible for designing, planning, and
implementing secure coding practices and security testing
methodologies?
-software security architect
3
, -product security developer
-software security champion
-software tester - ....ANSWER...-software security
architect
A potential threat was discovered during functional
testing of a file upload component when a QA analyst
was allowed to upload a shell script. Users should only
be allowed to upload image files. How should existing
security controls be adjusted to prevent this in the future?
-Validate all user input
-Enforce role-based authorization
-Ensure all data is encrypted in transit
-Force users to re-authenticate when accessing critical
functionality - ....ANSWER...-Validate all user input
4