WGU D487 SECURE SOFTWARE DESIGN
COMPREHENSIVE EXAM QUESTIONS AND
CORRECT ANSWERS COMPLETE STUDY
SHEET
●● Active Scanner
Answer: A security tool that actively probes a running application for
vulnerabilities.
●● Agile Methodology
Answer: Aims for customer satisfaction through early and continuous
delivery of useful software components developed by an iterative
process using the bare minimum requirements
●● Alpha Level Testing
Answer: Early-stage testing done internally by developers or testers
before releasing the product.
●● Application Decomposition
Answer: The process of breaking down an application into components
or modules to understand its structure.
●● Application Security
,Answer: Measures to secure applications throughout development
●● Application-Centric Threat Modeling
Answer: Threat modeling focused on application-specific components
●● AppSec
Answer: Short form of Application Security
●● Architecture (A2) Phase
Answer: the second phase of the security development life cycle that
examines security from perspective of business risks
●● Asset-Centric Threat Modeling
Answer: Threat modeling centered on protecting valuable assets.
●● Authenticated Scans
Answer: Scans using valid credentials to simulate internal user access
●● Benchmarks
Answer: baseline values the system seeks to attain
●● Beta Level Testing
, Answer: Testing performed by external users before final release.
●● Black Box Testing
Answer: Testing, either functional or non-functional, without reference
to the internal structure of the component or system.
●● Building Security In Maturity Model (BSIMM)
Answer: A model for evaluating software security programs.
●● Code Review
Answer: Examination of source code for bugs and security flaws.
●● Common Vulnerabilities and Exposures (CVE)
Answer: A list of known publicly disclosed cybersecurity vulnerabilities.
●● Common Vulnerability Scoring System (CVSS)
Answer: A framework for rating the severity of vulnerabilities.
●● Construction
Answer: The phase where software is coded and assembled.
●● Control Flow Analysis
COMPREHENSIVE EXAM QUESTIONS AND
CORRECT ANSWERS COMPLETE STUDY
SHEET
●● Active Scanner
Answer: A security tool that actively probes a running application for
vulnerabilities.
●● Agile Methodology
Answer: Aims for customer satisfaction through early and continuous
delivery of useful software components developed by an iterative
process using the bare minimum requirements
●● Alpha Level Testing
Answer: Early-stage testing done internally by developers or testers
before releasing the product.
●● Application Decomposition
Answer: The process of breaking down an application into components
or modules to understand its structure.
●● Application Security
,Answer: Measures to secure applications throughout development
●● Application-Centric Threat Modeling
Answer: Threat modeling focused on application-specific components
●● AppSec
Answer: Short form of Application Security
●● Architecture (A2) Phase
Answer: the second phase of the security development life cycle that
examines security from perspective of business risks
●● Asset-Centric Threat Modeling
Answer: Threat modeling centered on protecting valuable assets.
●● Authenticated Scans
Answer: Scans using valid credentials to simulate internal user access
●● Benchmarks
Answer: baseline values the system seeks to attain
●● Beta Level Testing
, Answer: Testing performed by external users before final release.
●● Black Box Testing
Answer: Testing, either functional or non-functional, without reference
to the internal structure of the component or system.
●● Building Security In Maturity Model (BSIMM)
Answer: A model for evaluating software security programs.
●● Code Review
Answer: Examination of source code for bugs and security flaws.
●● Common Vulnerabilities and Exposures (CVE)
Answer: A list of known publicly disclosed cybersecurity vulnerabilities.
●● Common Vulnerability Scoring System (CVSS)
Answer: A framework for rating the severity of vulnerabilities.
●● Construction
Answer: The phase where software is coded and assembled.
●● Control Flow Analysis