WGU D487 PRE-ASSESSMENT: SECURE SOFTWARE DESIGN
(KEO1) (PKEO) MOST TESTED QUESTIONS AND ANSWERS
GRADED A+ WITH RATIONALES
Question 1
What is a study of real-world software security initiatives organized so companies can measure
their initiatives and evolve them over time?
A. OWASP Top 10
B. ISO/IEC 27001
C. Building Security In Maturity Model (BSIMM)
D. NIST Cybersecurity Framework
Correct Answer: C
Rationale: BSIMM measures and compares real-world software security programs across
organizations.
Question 2
What type of analysis examines software without executing the program?
A. Dynamic analysis
B. Penetration testing
C. Static analysis
D. Functional testing
Correct Answer: C
Rationale: Static analysis reviews source code or binaries without runtime execution.
Question 3
Which ISO standard is the benchmark for information security today?
A. ISO 9001
B. ISO/IEC 15408
C. ISO/IEC 27001
D. ISO 31000
,ESTUDYR
Correct Answer: C
Rationale: ISO/IEC 27001 defines requirements for an information security management system
(ISMS).
Question 4
What type of analysis executes software on real or virtual processors in real time?
A. Static analysis
B. Code review
C. Dynamic analysis
D. Threat modeling
Correct Answer: C
Rationale: Dynamic analysis evaluates software behavior during execution.
Question 5
Who is responsible for designing, planning, and implementing secure coding practices and
security testing methodologies?
A. Product owner
B. Scrum master
C. Software security architect
D. QA analyst
Correct Answer: C
Rationale: The software security architect defines secure design and testing strategies.
Question 6
A well-documented feature is being added over a fixed 3–4 month period, with team members
dedicated solely to that feature. Which development methodology is being used?
A. Agile
B. Scrum
C. Kanban
D. Waterfall
Correct Answer: D
Rationale: Waterfall follows a sequential, fixed-scope, time-boxed approach.
, ESTUDYR
Question 7
Admins can access full functionality while normal users see limited information and no admin
features. Which principle is applied?
A. Separation of duties
B. Defense in depth
C. Principle of least privilege
D. Zero trust
Correct Answer: C
Rationale: Users are granted only the minimum permissions necessary.
Question 8
A daily meeting where scrum team members discuss yesterday’s work, today’s plan, and
blockers is called:
A. Sprint review
B. Sprint retrospective
C. Backlog refinement
D. Daily Scrum
Correct Answer: D
Rationale: The Daily Scrum is a short, time-boxed coordination meeting.
Question 9
Which list provides standardized names for publicly known vulnerabilities?
A. OWASP
B. CWE
C. Common Vulnerabilities and Exposures (CVE)
D. NVD
Correct Answer: C
Rationale: CVE assigns unique identifiers to known security vulnerabilities.