DESIGN EXAM LATEST 2024 ACTUAL EXAM 400 QUESTIONS
ws ws ws ws ws ws ws ws
AND CORRECT DETAILED ANSWERS WITH RATIONALES (VE
ws ws ws ws ws ws
RIFIED ANSWERS) |ALREADY GRADED A+ ws ws ws ws
What is a step for constructing a threat model for a project when using practical risk analysis?
ws ws ws ws ws ws ws ws ws ws ws ws ws ws ws ws
A Align your business goals
ws ws ws ws
B Apply engineering methods
ws ws ws
C Estimate probability of project time
ws ws ws ws ws
D Make a list of what you are trying to protect - ANSWER-D
ws ws ws ws ws ws ws ws ws ws ws ws
Which cyber threats are typically surgical by nature, have highly specific targeting, and are techn
ws ws ws ws ws ws ws ws ws ws ws ws ws ws
ologically sophisticated?
ws
A Tactical attacks
ws ws
B Criminal attacks
ws ws
C Strategic attacks
ws ws
D User-specific attacks - ANSWER-A
ws ws ws ws
Which type of cyberattacks are often intended to elevate awareness of a topic?
ws ws ws ws ws ws ws ws ws ws ws ws
A Cyberwarfare
ws
B Tactical attacks
ws ws
C User-specific attacks
ws ws
D Sociopolitical attacks - ANSWER-D
ws ws ws ws
What type of attack locks a user's desktop and then requires a payment to unlock it?
ws ws ws ws ws ws ws ws ws ws ws ws ws ws ws
A Phishing
ws
, WGU MASTER'S COURSE C706 - SECURE SOFTWARE
ws ws ws ws ws ws
DESIGN EXAM LATEST 2024 ACTUAL EXAM 400 QUESTIONS
ws ws ws ws ws ws ws ws
AND CORRECT DETAILED ANSWERS WITH RATIONALES (VE
ws ws ws ws ws ws
RIFIED ANSWERS) |ALREADY GRADED A+ ws ws ws ws
B Keylogger
ws
C Ransomware
ws
D Denial-of-service - ANSWER-C
ws ws ws
What is a countermeasure against various forms of XML and XML path injection attacks?
ws ws ws ws ws ws ws ws ws ws ws ws ws
A XML name wrapping
ws ws ws
B XML unicode encoding
ws ws ws
C XML attribute escaping
ws ws ws
D XML distinguished name escaping - ANSWER-C
ws ws ws ws ws ws
Which countermeasure is used to mitigate SQL injection attacks?
ws ws ws ws ws ws ws ws
A SQL Firewall
ws ws
B Projected bijection
ws ws
C Query parameterization
ws ws
D Progressive ColdFusion - ANSWER-C
ws ws ws ws
What is an appropriate countermeasure to an escalation of privilege attack?
ws ws ws ws ws ws ws ws ws ws
A Enforcing strong password policies
ws ws ws ws
B Using standard encryption algorithms and correct key sizes
ws ws ws ws ws ws ws ws
C Enabling the auditing and logging of all administration activities
ws ws ws ws ws ws ws ws ws
D Restricting access to specific operations through role-based access controls - ANSWER-D
ws ws ws ws ws ws ws ws ws ws ws
, WGU MASTER'S COURSE C706 - SECURE SOFTWARE ws ws ws ws ws ws
DESIGN EXAM LATEST 2024 ACTUAL EXAM 400 QUESTIONS
ws ws ws ws ws ws ws ws
AND CORRECT DETAILED ANSWERS WITH RATIONALES (VE
ws ws ws ws ws ws
RIFIED ANSWERS) |ALREADY GRADED A+ ws ws ws ws
Which configuration management security countermeasure implements least privilege access contr
ws ws ws ws ws ws ws ws ws
ol?
A Following strong password policies to restrict access
ws ws ws ws ws ws ws
B Restricting file access to users based on authorization
ws ws ws ws ws ws ws ws
C Avoiding clear text format for credentials and sensitive data
ws ws ws ws ws ws ws ws ws
D Using AES 256 encryption for communications of a sensitive nature - ANSWER-B
ws ws ws ws ws ws ws ws ws ws ws ws
Which phase of the software development life cycle (SDL/SDLC) would be used to determine t
ws ws ws ws ws ws ws ws ws ws ws ws ws ws
he minimum set of privileges required to perform the targeted task and restrict the user to a d
ws ws ws ws ws ws ws ws ws ws ws ws ws ws ws ws ws
omain with those privileges?
ws ws ws
A Design
ws
B Deploy
ws
C Development
ws
D Implementation - ANSWER-A
ws ws ws
Which least privilege method is more granular in scope and grants specific processes only the
ws ws ws ws ws ws ws ws ws ws ws ws ws ws ws
privileges necessary to perform certain required functions, instead of granting them unrestricted
ws ws ws ws ws ws ws ws ws ws ws
access to the system?
ws ws ws ws
A Entitlement privilege
ws ws
B Separation of privilege
ws ws ws
C Aggregation of privileges
ws ws ws
D Segregation of responsibilities - ANSWER-B
ws ws ws ws ws
Why does privilege creep pose a potential security risk?
ws ws ws ws ws ws ws ws
, WGU MASTER'S COURSE C706 - SECURE SOFTWARE ws ws ws ws ws ws
DESIGN EXAM LATEST 2024 ACTUAL EXAM 400 QUESTIONS
ws ws ws ws ws ws ws ws
AND CORRECT DETAILED ANSWERS WITH RATIONALES (VE
ws ws ws ws ws ws
RIFIED ANSWERS) |ALREADY GRADED A+ ws ws ws ws
A User privileges do not match their job role.
ws ws ws ws ws ws ws ws
B With more privileges, there are more responsibilities.
ws ws ws ws ws ws ws
C Auditing will show a mismatch between individual responsibilities and their access rights.
ws ws ws ws ws ws ws ws ws ws ws ws
D Users have more privileges than they need and may perform actions outside their job descrip
ws ws ws ws ws ws ws ws ws ws ws ws ws ws ws
tion. - ANSWER-D
ws ws
A system developer is implementing a new sales system. The system developer is concerned that
ws ws ws ws ws ws ws ws ws ws ws ws ws ws
unauthorized individuals may be able to view sensitive customer financial data.
ws ws ws ws ws ws ws ws ws ws ws
Which family of nonfunctional requirements should be considered as part of the acceptance criter
ws ws ws ws ws ws ws ws ws ws ws ws ws
ia?
A Integrity
ws
B Availability
ws
C Nonrepudition
ws
D Confidentiality - ANSWER-D
ws ws ws
A project manager is given the task to come up with nonfunctional acceptance criteria requirem
ws ws ws ws ws ws ws ws ws ws ws ws ws ws
ents for business owners as part of a project delivery.
ws ws ws ws ws ws ws ws ws
Which nonfunctional requirement should be applied to the acceptance criteria?
ws ws ws ws ws ws ws ws ws
A Give search options to users
ws ws ws ws ws
B Evaluate test execution results
ws ws ws ws
C Divide users into groups and give them separate rights
ws ws ws ws ws ws ws ws ws
D Develop software that keeps downward compatibility intact - ANSWER-B
ws ws ws ws ws ws ws ws ws