100% de satisfacción garantizada Inmediatamente disponible después del pago Tanto en línea como en PDF No estas atado a nada 4,6 TrustPilot
logo-home
Examen

WGU D487 Secure Software Design (LATEST 2025 / 2026 UPDATE), ACTUAL EXAM/TEST QUESTIONS AND 100% VERIFIED ANSWERS | A+ GRADE

Puntuación
-
Vendido
-
Páginas
32
Grado
A+
Subido en
21-07-2025
Escrito en
2024/2025

This document provides a comprehensive set of actual exam-style questions and verified answers for WGU D487 Secure Software Design. It covers the Software Development Life Cycle (SDL) phases, PSIRT activities, secure coding best practices, various requirements, threat modeling techniques, vulnerability management, and database security. This material is an excellent resource for WGU students preparing for their D487 exams.

Mostrar más Leer menos
Institución
D487
Grado
D487











Ups! No podemos cargar tu documento ahora. Inténtalo de nuevo o contacta con soporte.

Escuela, estudio y materia

Institución
D487
Grado
D487

Información del documento

Subido en
21 de julio de 2025
Número de páginas
32
Escrito en
2024/2025
Tipo
Examen
Contiene
Preguntas y respuestas

Temas

Vista previa del contenido

WGU D487 Secure
Software Design
(LATEST
UPDATE), ACTUAL
EXAM/TEST
QUESTIONS AND
100% VERIFIED
ANSWERS | A+
GRADE

,Question 1:

What are Security testing reports used for in A5 Ship?
Correct Answer:
They document findings from different types of security testing in this phase of the SDL.

Question 2:

What is the next step after the PSIRT determines a vulnerability is
credible and high severity?
Correct Answer:
Identify resources and schedule the fix

Question 3:
which secure coding best practice uses well-tested, publicly available
algorithms to hide product data from unauthorized access?
Correct Answer:
cryptographic practice

Question 4:

What is the next step for the Product Security Incident Response Team
(PSIRT) after developing and testing a patch?
Correct Answer:

✔ Notify customers that the fix is available

Question 5:
Which type of requirement specifies that user passwords will require a
minimum of 8 characters and must include at least one uppercase
character, one number, and one special character?
Correct Answer:
Privacy requirement

Question 6:

What is the purpose of Updated threat modeling artifacts in A3 Design &
Development?
Correct Answer:
To maintain data flow diagrams, elements, and threat listings for security analysis.

Question 7:
Security Assessment

,What are the key activities in the Security Assessment phase of SDL?
Correct Answer:
SDL Phase 1 (A1) = SDLC 1 Concept

Software security team is looped in early
Security team hosts a discovery meeting
Software security team discusses project plan
States what further work will be done
Privacy Impact Assessment (PIA) plan is created

Question 8:
SSDL BSIMM
Correct Answer:

SSDL Touchpoints in BSIMM focuses on activities directly related to the software security development lifecycle
(SSDL), including security testing, code review, and architecture analysis.


Question 9:

What is the Open-source licensing review report used for in A5 Ship?
Correct Answer:
To review compliance with licensing requirements if open-source software is used.

Question 10:
What does PSIRT use CVSS scoring for?
Correct Answer:
To prioritize responses to externally discovered vulnerabilities
To determine the severity of security incidents
To modify scores based on factors not captured in the standard CVSS model

Question 11:

What is an Every-Sprint Requirement in Agile SDL?
Correct Answer:

✔ Recurring security tasks that must be implemented in each sprint.

✔ Examples: Input validation, threat modeling, static code analysis.

✔ Ensures continuous security integration throughout development.


Question 12:
What are the four severity levels in CVSS scoring?
Correct Answer:

Critical (C) – CVSS base score of 9.0–10.0

High (H) – CVSS base score of 7.0–8.9

, Medium (M) – CVSS base score of 4.0–6.9

Low (L) – CVSS base score of 0.1–3.9


Question 13:

How should software development organizations handle privacy
response plans?
Correct Answer:

They should either:

Develop their own privacy response plans

Modify the Microsoft SDL Privacy Escalation Response Framework to fit their organization’s needs.


Question 14:
Security Testing Reports
Correct Answer:
A findings summary should be prepared for each type of security testing: manual code review, static analysis,
dynamic analysis, penetration testing, and fuzzing. The reports should provide the type and number of issues
identified and any consistent theme that can be derived from the findings. A4 D&D

Question 15:

What are the four focus areas of BSIMM?
Correct Answer:

Governance – Managing security initiatives.

Intelligence – Collecting security knowledge and tools.

SSDL Touchpoints – Applying security to the software development lifecycle.

Deployment – Security controls for operations.


Question 16:

What does the acronym DREAD stand for in Microsoft's risk model?
Correct Answer:
Damage potential, Reproducibility, Exploitability, Affected users, Discoverability

Question 17:
DREAD
Correct Answer:
$12.98
Accede al documento completo:

100% de satisfacción garantizada
Inmediatamente disponible después del pago
Tanto en línea como en PDF
No estas atado a nada

Conoce al vendedor

Seller avatar
Los indicadores de reputación están sujetos a la cantidad de artículos vendidos por una tarifa y las reseñas que ha recibido por esos documentos. Hay tres niveles: Bronce, Plata y Oro. Cuanto mayor reputación, más podrás confiar en la calidad del trabajo del vendedor.
MedTechStudyHub Chamberlain College Of Nursing
Seguir Necesitas iniciar sesión para seguir a otros usuarios o asignaturas
Vendido
37
Miembro desde
1 año
Número de seguidores
2
Documentos
1244
Última venta
6 días hace
BrainBooster

Get access to 100% verified exams, test banks, and study guides for ATI, NURSING, PMHNP, TNCC, USMLE, ACLS, WGU, and many more! We guarantee authentic, high-quality content designed to help you ace your exams with confidence. If you can’t find what you’re looking for, simply contact us — we’ll fetch it for you within minutes! ✅ Trusted by thousands of students ✅ Fast delivery & verified accuracy ✅ Guaranteed success on your next exam Buy with confidence — success starts here!

Lee mas Leer menos
4.3

12 reseñas

5
7
4
3
3
1
2
1
1
0

Recientemente visto por ti

Por qué los estudiantes eligen Stuvia

Creado por compañeros estudiantes, verificado por reseñas

Calidad en la que puedes confiar: escrito por estudiantes que aprobaron y evaluado por otros que han usado estos resúmenes.

¿No estás satisfecho? Elige otro documento

¡No te preocupes! Puedes elegir directamente otro documento que se ajuste mejor a lo que buscas.

Paga como quieras, empieza a estudiar al instante

Sin suscripción, sin compromisos. Paga como estés acostumbrado con tarjeta de crédito y descarga tu documento PDF inmediatamente.

Student with book image

“Comprado, descargado y aprobado. Así de fácil puede ser.”

Alisha Student

Preguntas frecuentes