Rédigé par des étudiants ayant réussi Disponible immédiatement après paiement Lire en ligne ou en PDF Mauvais document ? Échangez-le gratuitement 4,6 TrustPilot
logo-home
Document preview thumbnail
Aperçu 3 sur 26 pages
Examen

WGU C706 Secure Software Design – Western Governors University – Study Guide Questions and Answers (Latest Updated 2026/2027)

Document preview thumbnail
Aperçu 3 sur 26 pages

This document contains study guide questions and answers for the WGU C706 Secure Software Design course. It covers essential topics including secure software development lifecycle (SDLC), secure design principles, threat modeling, risk assessment, authentication, authorization, cryptography, application security, secure coding practices, and software security testing. The material is presented in an easy-to-review question-and-answer format, making it ideal for exam preparation and reinforcing key concepts. It serves as a comprehensive study resource aligned with the WGU C706 course objective

Aperçu du contenu

WGU C706 Secure Software Design Study Guide Questions
and Answers Latest Updated 2026/2027.Great success
Assured



Confidentiality - ✅✅Information is not made available or disclosed to unauthorized
individuals, entities, or processes. Ensures unauthorized persons are not able to read private
and sensitive data. It is achieved through cryptography.



1. Integrity - ✅✅Ensures unauthorized persons or channels are not able to modify the
data. It is accomplished through the use of a message digest or digital signatures.



2. Availability - ✅✅The computing systems used to store and process information, the
security controls used to protect information, and the communication channels used to
access information must be functioning correctly. Ensures system remains operational
even in the event of a failure or an attack. It is achieved by providing redundancy or fault
tolerance for a failure of a system and its components.



3. Ensure Confidentiality - ✅✅Public Key Infrastructure (PKI) and
Cryptography/Encryption



4. Ensure Availability - ✅✅Offsite back-up and Redundancy



5. Ensure Integrity - ✅✅Hashing, Message Digest (MD5), non repudiation and digital
signatures



6. Software Architect - ✅✅Moves analysis to implementation and analyzes the
requirements and use cases as activities to perform as part of the development process;
can also develop class diagrams.



7. Security Practitioner Roles - ✅✅Release Manager,
8. Architect, Developer, Business Analyst/Project Manager


P a g e 1 | 19

,9. Release Manager - ✅✅Deployment



10. Architect - ✅✅Design



11. Developer - ✅✅Coding



12. Business Analyst/Project Manager - ✅✅Requirements Gathering



13. Red Team - ✅✅Teams of people familiar with the infrastructure of the company and
the languages of the software being developed. Their mission is to kill the system as the
developers build it.



14. Static Analysis - ✅✅A method of computer program debugging that is done by
examining the code without executing the program. The process provides an
understanding of the code structure, and can help to ensure that the code adheres to
industry standards. It's also referred as code review.



15. MD5 Hash - ✅✅A widely used hash function producing a 128-bit hash value. Initially
designed to be used as a cryptographic hash function, it has been found to suffer from
extensive vulnerabilities. It can still be used as a checksum to verify data integrity, but
only against unintentional corruption.



16. SHA-256 (Secure Hash Algorithm) - ✅✅One of a number of cryptographic hash
functions. A cryptographic hash is like a signature for a text or a data file. Generates an
almost-unique, fixed size 32-byte
17. (32 X 8) hash. Hash is a one-way function - it cannot be decrypted.



18. Advanced Encryption Standard (AES) - ✅✅A symmetric encryption algorithm. The
algorithm was developed by two Belgian cryptographers Joan Daemen and Vincent

P a g e 2 | 19

, Rijmen. Designed to be efficient in both hardware and software, and supports a block
length of 128 bits and key lengths of 128, 192, and 256 bits.



19. Algorithms used to verify integrity - ✅✅MD5 Hash, SHA-256



20. Algorithm used to verify confidentiality - ✅✅Advanced Encryption Standard (AES)



21. Stochastic - ✅✅unintentional or accidental



22. safety-relevant faults - ✅✅stochastic (i.e., unintentional or accidental)



23. security-relevant faults - ✅✅"Sponsored," i.e., intentionally created and activated
through conscious and intentional human agency.



24. Fuzz Testing - ✅✅Used to see if the system has solid exception handling to the input it
receives. Is the use of malformed or random input into a system in order to intentionally
produce failure. This is a very easy process of feeding garbage to the system when it
expects a formatted input, and it is always a good idea to feed as much garbage as
possible to an input field.



25. Three (3) Tier - ✅✅Removes the business logic from the client end of the system. It
generally places the business logic on a separate server from the client. The data access
portion of the system resides separately from both the client and the business logic
platform.



26. T-MAP - ✅✅Defines a set of threat-relevant attributes for each layer or node. These
can be classified as probability-relevant, size-of-loss relevant, or descriptive. These are
primarily derived from Common Vulnerability Scoring System (CVSS). USC's Threat
Modeling based on Attacking Path analysis is a risk management approach that

P a g e 3 | 19

Infos sur le Document

Publié le
19 juillet 2026
Nombre de pages
26
Écrit en
2025/2026
Type
Examen
Contenu
Questions et réponses
14,67 €

Mauvais document ? Échangez-le gratuitement Dans les 14 jours suivant votre achat et avant le téléchargement, vous pouvez choisir un autre document. Vous pouvez simplement dépenser le montant à nouveau.
Rédigé par des étudiants ayant réussi
Disponible immédiatement après paiement
Lire en ligne ou en PDF

Seller avatar
Les scores de réputation sont basés sur le nombre de documents qu'un vendeur a vendus contre paiement ainsi que sur les avis qu'il a reçu pour ces documents. Il y a trois niveaux: Bronze, Argent et Or. Plus la réputation est bonne, plus vous pouvez faire confiance sur la qualité du travail des vendeurs.
TUTOROUINE
3,1
(10)
Vendu
48
Abonnés
0
Éléments
1667
Dernière vente
7 heures de cela



Pourquoi les étudiants choisissent Stuvia

Créé par d'autres étudiants, vérifié par les avis

Une qualité sur laquelle compter : rédigé par des étudiants qui ont réussi et évalué par d'autres qui ont utilisé ce document.

Le document ne convient pas ? Choisis un autre document

Aucun souci ! Tu peux sélectionner directement un autre document qui correspond mieux à ce que tu cherches.

Paye comme tu veux, apprends aussitôt

Aucun abonnement, aucun engagement. Paye selon tes habitudes par carte de crédit et télécharge ton document PDF instantanément.

Student with book image

“Acheté, téléchargé et réussi. C'est aussi simple que ça.”

Alisha Student

Vous travaillez sur vos références ?

Créez des citations précises en APA, MLA et Harvard avec notre générateur de sources gratuit.

Vous travaillez sur vos références ?

Foire aux questions