WGU D487 SECURE SOFTWARE DESIGN
EXAMINATION PREP STUDY GUIDE LATEST
UPDATED PRACTICE SOLUTION VERIFIED 100
PERCENT
◉ SDLC. Answer: Software Development Life Cycle; the normal
process for planning, building, testing, releasing, and maintaining
software.
◉ SDL. Answer: Security Development Lifecycle; security activities
integrated into each SDLC phase so security is built in rather than
added at the end.
◉ Secure software. Answer: Software that protects confidentiality,
integrity, and availability while meeting its intended function.
◉ Software security. Answer: The discipline of preventing, finding,
and fixing security weaknesses in software throughout its life cycle.
◉ Security assurance. Answer: Confidence that software security
controls and processes are effective and appropriate for the product's
risk.
,◉ CIA triad. Answer: Confidentiality, integrity, and availability; the
three core security goals.
◉ Confidentiality. Answer: Protecting information from unauthorized
disclosure.
◉ Integrity. Answer: Protecting data or systems from unauthorized or
improper modification.
◉ Availability. Answer: Ensuring systems and data are accessible
when needed.
◉ Attack surface. Answer: The set of exposed entry points, interfaces,
data flows, privileges, and code paths an attacker could target.
◉ Attack surface validation. Answer: Testing and reviewing exposed
attack paths to confirm they are minimized and protected.
◉ Threat modeling. Answer: A structured process for identifying
assets, attackers, entry points, threats, vulnerabilities, and mitigations.
◉ Threat. Answer: A potential event or actor that could cause harm to
a system or asset.
◉ Vulnerability. Answer: A weakness in software, design,
configuration, or process that can be exploited.
,◉ Exploit. Answer: A technique, code, or method used to take
advantage of a vulnerability.
◉ Attack. Answer: An action taken against a target system; often
carried out using an exploit.
◉ Mitigation. Answer: A control or design change that reduces the
likelihood or impact of a threat.
◉ Risk. Answer: The combination of likelihood and impact of a threat
exploiting a vulnerability.
◉ Likelihood. Answer: The probability that a threat will occur or a
vulnerability will be exploited.
◉ Impact. Answer: The amount of harm caused if a risk is realized.
◉ Risk ranking. Answer: Prioritizing threats or vulnerabilities based
on severity, likelihood, impact, or scoring models.
◉ Risk acceptance. Answer: A formal decision to release or continue
operating with a known risk.
◉ Security requirement. Answer: A required security behavior,
control, or constraint the software must satisfy.
, ◉ Privacy requirement. Answer: A requirement related to proper
collection, use, storage, disclosure, retention, or deletion of personal
data.
◉ Nonfunctional requirement. Answer: A requirement describing
system qualities such as security, performance, reliability, privacy, or
compliance.
◉ Least privilege. Answer: Granting users, processes, and systems
only the minimum access necessary to perform their function.
◉ Defense in depth. Answer: Using multiple layers of controls so
failure of one control does not fully compromise the system.
◉ Secure by design. Answer: Designing architecture and features
with security controls and threat resistance from the start.
◉ Shift left. Answer: Moving security activities earlier in the
development life cycle to find and fix issues sooner.
◉ Security champion. Answer: A development-team member who
promotes secure practices and helps scale security knowledge inside
the team.
EXAMINATION PREP STUDY GUIDE LATEST
UPDATED PRACTICE SOLUTION VERIFIED 100
PERCENT
◉ SDLC. Answer: Software Development Life Cycle; the normal
process for planning, building, testing, releasing, and maintaining
software.
◉ SDL. Answer: Security Development Lifecycle; security activities
integrated into each SDLC phase so security is built in rather than
added at the end.
◉ Secure software. Answer: Software that protects confidentiality,
integrity, and availability while meeting its intended function.
◉ Software security. Answer: The discipline of preventing, finding,
and fixing security weaknesses in software throughout its life cycle.
◉ Security assurance. Answer: Confidence that software security
controls and processes are effective and appropriate for the product's
risk.
,◉ CIA triad. Answer: Confidentiality, integrity, and availability; the
three core security goals.
◉ Confidentiality. Answer: Protecting information from unauthorized
disclosure.
◉ Integrity. Answer: Protecting data or systems from unauthorized or
improper modification.
◉ Availability. Answer: Ensuring systems and data are accessible
when needed.
◉ Attack surface. Answer: The set of exposed entry points, interfaces,
data flows, privileges, and code paths an attacker could target.
◉ Attack surface validation. Answer: Testing and reviewing exposed
attack paths to confirm they are minimized and protected.
◉ Threat modeling. Answer: A structured process for identifying
assets, attackers, entry points, threats, vulnerabilities, and mitigations.
◉ Threat. Answer: A potential event or actor that could cause harm to
a system or asset.
◉ Vulnerability. Answer: A weakness in software, design,
configuration, or process that can be exploited.
,◉ Exploit. Answer: A technique, code, or method used to take
advantage of a vulnerability.
◉ Attack. Answer: An action taken against a target system; often
carried out using an exploit.
◉ Mitigation. Answer: A control or design change that reduces the
likelihood or impact of a threat.
◉ Risk. Answer: The combination of likelihood and impact of a threat
exploiting a vulnerability.
◉ Likelihood. Answer: The probability that a threat will occur or a
vulnerability will be exploited.
◉ Impact. Answer: The amount of harm caused if a risk is realized.
◉ Risk ranking. Answer: Prioritizing threats or vulnerabilities based
on severity, likelihood, impact, or scoring models.
◉ Risk acceptance. Answer: A formal decision to release or continue
operating with a known risk.
◉ Security requirement. Answer: A required security behavior,
control, or constraint the software must satisfy.
, ◉ Privacy requirement. Answer: A requirement related to proper
collection, use, storage, disclosure, retention, or deletion of personal
data.
◉ Nonfunctional requirement. Answer: A requirement describing
system qualities such as security, performance, reliability, privacy, or
compliance.
◉ Least privilege. Answer: Granting users, processes, and systems
only the minimum access necessary to perform their function.
◉ Defense in depth. Answer: Using multiple layers of controls so
failure of one control does not fully compromise the system.
◉ Secure by design. Answer: Designing architecture and features
with security controls and threat resistance from the start.
◉ Shift left. Answer: Moving security activities earlier in the
development life cycle to find and fix issues sooner.
◉ Security champion. Answer: A development-team member who
promotes secure practices and helps scale security knowledge inside
the team.