100% de satisfacción garantizada Inmediatamente disponible después del pago Tanto en línea como en PDF No estas atado a nada 4.2 TrustPilot
logo-home
Examen

D385 Software Security and Testing – 100 Exam Q&A | Python, XSS, API Security, CORS | 2025/2026 | WGU

Puntuación
-
Vendido
-
Páginas
26
Grado
A+
Subido en
08-11-2025
Escrito en
2025/2026

This document features 100 updated and verified exam questions and answers for the D385 Software Security and Testing course offered by Western Governors University (WGU) for the 2025/2026 academic year. Specifically tailored for WGU students, it serves as a comprehensive and practical guide for mastering secure coding, API security, authentication protocols, error handling, and Python-based vulnerability prevention techniques. The content emphasizes real-world software security threats and testing techniques with code-based examples and memorization tips. It is particularly useful for students studying cybersecurity, software development, and secure systems engineering. The questions reflect real exam formatting and highlight correct answers and edge-case scenarios that often appear in WGU assessments. Key topics include: OWASP vulnerabilities: Cross-Site Scripting (XSS), SQL Injection, Broken Access Control Python security coding: use of eval(), validate(), assert, type(), isinstance() Secure logging and input handling: preventing log injection, using assertions, type checking Common attacks and defense: Man-in-the-Middle, DoS, code injection, token mismanagement API and HTTP protocol handling: status codes (200–500), headers (Authentication, User-Agent, CORS) Secure communication practices: token caching (MSAL), rate limiting, proper error response handling Serialization, hashing, and encryption: 3_256, AES CTR mode, secure deserialization Testing techniques: regression testing, preconditions/postconditions, response validation Ideal for: WGU students enrolled in the D385 course Software development and cybersecurity majors Python developers learning to implement secure practices Professionals preparing for software testing or secure coding certifications Anyone working with REST APIs, logging, or access control mechanisms With complete code examples, common output interpretations, and detailed reasoning behind the correct choices, this guide is optimized for both learning and high exam performance. Keywords: software security, WGU D385, Python secure coding, XSS, SQL injection, API security, CORS, HTTP status codes, assertion, eval, sanitize input, authentication headers, log injection, hashing, AES encryption, deserialization, access control, regression testing, secure REST API, man-in-the-middle, error handling

Mostrar más Leer menos
Institución
Grado










Ups! No podemos cargar tu documento ahora. Inténtalo de nuevo o contacta con soporte.

Escuela, estudio y materia

Institución
Grado

Información del documento

Subido en
8 de noviembre de 2025
Número de páginas
26
Escrito en
2025/2026
Tipo
Examen
Contiene
Preguntas y respuestas

Temas

Vista previa del contenido

D385 Software Security and Testing
2025/2026 Exam Questions and Correct
Answers | New Update



Sanitize outbound log messages - 🧠 ANSWER ✔✔What is the primary

defense against log injection attacks?


Access the user's data - 🧠 ANSWER ✔✔An attacker exploits a cross-site

scripting vulnerability. What is the attacker able to do?


eval() - 🧠 ANSWER ✔✔Which Python function is prone to a potential code

injection attack?


Check functional preconditions and postconditions - 🧠 ANSWER ✔✔What

are two common defensive coding techniques?


test - 🧠 ANSWER ✔✔Which package is meant for internal use by Python

for regression testing?

,type() - 🧠 ANSWER ✔✔Which Python function is used for input validation?


Broken access control - 🧠 ANSWER ✔✔A security analyst has noticed a

vulnerability in which an attacker took over multiple users' accounts. Which

vulnerability did the security analyst encounter?


Implement resource and field-level access control - 🧠 ANSWER ✔✔When

creating a new user, an administrator must submit the following fields to an

API endpoint:




Name

Email Address

Password

IsAdmin




What is the best way to ensure the API is protected against privilege

escalation?


Exploiting query parameters - 🧠 ANSWER ✔✔Which method is used for a

SQL injection attack?

, response.content - 🧠 ANSWER ✔✔Which response method, when sent a

request, returns information about the server's response and is delivered

back to the console?


Override same starting policy for specific resources - 🧠 ANSWER ✔✔What

does cross-origin resource sharing (CORS) allow users to do?


MSAL - 🧠 ANSWER ✔✔Which protocol caches a token after it has been

acquired?


200 - 🧠 ANSWER ✔✔OK - Your request was successful


201 - 🧠 ANSWER ✔✔CREATED - Your request was accepted, and the

resource was created


400 - 🧠 ANSWER ✔✔BAD REQUEST - Your request is either wrong or

missing information


401 - 🧠 ANSWER ✔✔UNAUTHORIZED - Your request requires additional

permissions


403 - 🧠 ANSWER ✔✔FORBIDDEN - website can be reached, but more

permissions needed before accessing further




COPYRIGHT©PROFFKERRYMARTIN 2025/2026. YEAR PUBLISHED 2025. COMPANY REGISTRATION NUMBER: 619652435. TERMS OF USE.
PRIVACY STATEMENT. ALL RIGHTS RESERVED
$15.49
Accede al documento completo:

100% de satisfacción garantizada
Inmediatamente disponible después del pago
Tanto en línea como en PDF
No estas atado a nada


Documento también disponible en un lote

Conoce al vendedor

Seller avatar
Los indicadores de reputación están sujetos a la cantidad de artículos vendidos por una tarifa y las reseñas que ha recibido por esos documentos. Hay tres niveles: Bronce, Plata y Oro. Cuanto mayor reputación, más podrás confiar en la calidad del trabajo del vendedor.
PROFFKERRYMARTIN Liberty University
Seguir Necesitas iniciar sesión para seguir a otros usuarios o asignaturas
Vendido
120
Miembro desde
10 meses
Número de seguidores
2
Documentos
8014
Última venta
1 día hace
KERRYMARTIN

KERRYMARTIN EXAM HUB Assignments, Case Studies, Research, Essay writing service, Questions and Answers, Discussions etc. for students who want to see results twice as fast. I have done papers of various topics and complexities. I am punctual and always submit work on-deadline. I write engaging and informative content on all subjects. Send me your research papers, case studies, psychology papers, etc, and I’ll do them to the best of my abilities. Writing is my passion when it comes to academic work. I’ve got a good sense of structure and enjoy finding interesting ways to deliver information in any given paper. I love impressing clients with my work, and I am very punctual about deadlines. Send me your assignment and I’ll take it to the next level. I strive for my content to be of the highest quality. Your wishes come first— send me your requirements and I’ll make a piece of work with fresh ideas, consistent structure, and following the academic formatting rules. For every student you refer to me with an order that is completed and paid transparently, I will do one assignment for you, free of charge!!!!!!!!!!!!

Lee mas Leer menos
3.3

23 reseñas

5
9
4
2
3
5
2
1
1
6

Recientemente visto por ti

Por qué los estudiantes eligen Stuvia

Creado por compañeros estudiantes, verificado por reseñas

Calidad en la que puedes confiar: escrito por estudiantes que aprobaron y evaluado por otros que han usado estos resúmenes.

¿No estás satisfecho? Elige otro documento

¡No te preocupes! Puedes elegir directamente otro documento que se ajuste mejor a lo que buscas.

Paga como quieras, empieza a estudiar al instante

Sin suscripción, sin compromisos. Paga como estés acostumbrado con tarjeta de crédito y descarga tu documento PDF inmediatamente.

Student with book image

“Comprado, descargado y aprobado. Así de fácil puede ser.”

Alisha Student

Preguntas frecuentes