100% de satisfacción garantizada Inmediatamente disponible después del pago Tanto en línea como en PDF No estas atado a nada 4.2 TrustPilot
logo-home
Examen

WGU D487 Secure Software Design Exam 2025/2026 | Version 3 Test Bank | 100+ Questions with OWASP & NIST Rationales | OA Practice Exam

Puntuación
-
Vendido
-
Páginas
24
Grado
A+
Subido en
01-12-2025
Escrito en
2025/2026

MASTER WGU D487 SECURE SOFTWARE DESIGN (VERSION 3) FOR THE 2025/2026 ACADEMIC YEAR! This comprehensive test bank features 100+ questions with answer keys that include concise security rationales citing current OWASP Top 10 and NIST standards—exactly what you need to pass your Objective Assessment and excel in cybersecurity. Unlike generic test banks, this resource is specifically tailored to WGU's Version 3 curriculum. Each question challenges your understanding of secure software design principles, while every rationale references current industry standards from OWASP and NIST, ensuring you're learning practical, real-world security practices that align with your OA and future career. WHAT MAKES THIS D487 RESOURCE ESSENTIAL: 100+ TARGETED QUESTIONS for WGU D487 Secure Software Design (Version 3, 2025/2026) OWASP & NIST-REFERENCED RATIONALES - Every answer includes current security standard citations VERSION-SPECIFIC CONTENT - Updated for Version 3 curriculum and assessment requirements OA-READY PRACTICE EXAM - Questions structured like the actual Objective Assessment CURRENT SECURITY STANDARDS - Covers OWASP Top 10 2021, NIST SP 800-53, and secure SDLC principles Stop struggling with outdated materials. Get the version-specific test bank that actually prepares you for the WGU D487 OA. Purchase now and master secure software design with confidence!

Mostrar más Leer menos
Institución
WGU D487 Secure Software Design
Grado
WGU D487 Secure Software Design










Ups! No podemos cargar tu documento ahora. Inténtalo de nuevo o contacta con soporte.

Escuela, estudio y materia

Institución
WGU D487 Secure Software Design
Grado
WGU D487 Secure Software Design

Información del documento

Subido en
1 de diciembre de 2025
Número de páginas
24
Escrito en
2025/2026
Tipo
Examen
Contiene
Preguntas y respuestas

Temas

Vista previa del contenido

1



WGU D487 Secure Software Design Exam
2025/2026 | Version 3 Test Bank | 100+
Questions with OWASP & NIST Rationales |
OA Practice Exam

1. Which activity appears first in a secure SDLC?
A. Penetration testing
B. Security requirements elicitation
C. Static code scanning
D. Deployment hardening
Answer: B
Rationale: NIST SP 800-64: security is cheapest and most effective when begun during
requirements ("shift-left").
2. The STRIDE acronym helps designers enumerate:
A. Security patterns
B. Threat categories
C. Cryptographic modes
D. Risk matrices
Answer: B
Rationale: STRIDE = Spoofing, Tampering, Repudiation, Information Disclosure, DoS,
Elevation of Privilege (OWASP Threat Modeling).
3. The primary goal of “Fail Securely” is that after any failure the system:
A. Reboots automatically
B. Returns an error code to the user
C. Remains in a safe state
D. Logs the stack trace
Answer: C
Rationale: OWASP design principle: default to a secure state on failure to deny attackers
an advantage.

, 2



4. Defense-in-depth is best described as:
A. Duplicate servers for HA
B. Multiple, layered security controls
C. Two-person code review
D. Encrypting every database column
Answer: B
Rationale: Layered controls ensure single failures don’t compromise the whole system
(NIST CSF).
5. The Open-Design principle states security must NOT depend on:
A. Strong crypto
B. Secrecy of the algorithm
C. Key confidentiality
D. Correct code
Answer: B
Rationale: Kerckhoffs/OWASP: assume attackers know the design; only keys must stay
secret.
6. Which authentication factor does a one-time SMS code represent?
A. Something you have
B. Something you are
C. Something you know
D. Somewhere you are
Answer: A
Rationale: The phone (SIM) is the possessed factor, per NIST SP 800-63B.
7. The best protection against SQL injection is:
A. Single quotes escaping
B. Stored procedures
C. Parameterized queries / prepared statements
D. Client-side validation
Answer: C
Rationale: Parameterization enforces separation between code and data, making
injection syntactically impossible (OWASP Top 10).
8. Which hashing scheme is currently recommended for passwords?
A. MD5 with salt

, 3



B. SHA-1 with pepper
C. bcrypt or Argon2 with per-user salt
D. RIPEMD-160
Answer: C
Rationale: Adaptive, CPU-hard algorithms resist parallel brute force; NIST SP 800-63B
approves such schemes.
9. Session fixation is best mitigated by:
A. Setting httpOnly flag
B. Regenerating session ID after login
C. Using 128-bit session tokens
D. Storing ID in local-storage
Answer: B
Rationale: Issuing a new unpredictable ID after authentication prevents attacker-supplied
IDs from being used (OWASP Cheat Sheet).
10. A digital signature gives the recipient confidence in:
A. Confidentiality
B. Integrity & origin
C. Availability
D. Perfect-forward secrecy
Answer: B
Rationale: Asymmetric signature verifies sender (non-repudiation) and that message
hasn’t been altered (NIST SP 800-89).
11. The “D” in DREAD risk scoring stands for:
A. Detection difficulty
B. Damage potential
C. Data classification
D. Deployment cost
Answer: B
Rationale: Microsoft DREAD: Damage, Reproducibility, Exploitability, Affected users,
Discoverability.
12. Which item is NOT part of a threat model diagram?
A. Data-flow arrows
B. Trust boundaries
$15.49
Accede al documento completo:

100% de satisfacción garantizada
Inmediatamente disponible después del pago
Tanto en línea como en PDF
No estas atado a nada

Conoce al vendedor

Seller avatar
Los indicadores de reputación están sujetos a la cantidad de artículos vendidos por una tarifa y las reseñas que ha recibido por esos documentos. Hay tres niveles: Bronce, Plata y Oro. Cuanto mayor reputación, más podrás confiar en la calidad del trabajo del vendedor.
STUVIASTUDYGUIDE University Of California - Los Angeles (UCLA)
Seguir Necesitas iniciar sesión para seguir a otros usuarios o asignaturas
Vendido
585
Miembro desde
2 año
Número de seguidores
199
Documentos
4012
Última venta
2 horas hace
STUVIASTUDYGUIDES

Join Thousands of successful students who use our study materials to boost their grades. With carefully crafted notes and well-researched guides, you're just a click away from mastering your courses. Study hard, study smart, and get the grades you deserve!

3.5

74 reseñas

5
32
4
11
3
10
2
7
1
14

Recientemente visto por ti

Por qué los estudiantes eligen Stuvia

Creado por compañeros estudiantes, verificado por reseñas

Calidad en la que puedes confiar: escrito por estudiantes que aprobaron y evaluado por otros que han usado estos resúmenes.

¿No estás satisfecho? Elige otro documento

¡No te preocupes! Puedes elegir directamente otro documento que se ajuste mejor a lo que buscas.

Paga como quieras, empieza a estudiar al instante

Sin suscripción, sin compromisos. Paga como estés acostumbrado con tarjeta de crédito y descarga tu documento PDF inmediatamente.

Student with book image

“Comprado, descargado y aprobado. Así de fácil puede ser.”

Alisha Student

Preguntas frecuentes