Geschreven door studenten die geslaagd zijn Direct beschikbaar na je betaling Online lezen of als PDF Verkeerd document? Gratis ruilen 4,6 TrustPilot
logo-home
Tentamen (uitwerkingen)

WGU D487 SECURE SOFTWARE DESIGN 2026/2027 | OA & Pre-Assessment Exam | Complete Verified Answers | A+ Grade | Pass Guaranteed

Beoordeling
-
Verkocht
-
Pagina's
33
Cijfer
A+
Geüpload op
04-06-2026
Geschreven in
2025/2026

Pass the WGU D487 Secure Software Design OA and Pre-Assessment exam with this complete 2026/2027 guide featuring verified answers. This A+ Graded resource contains comprehensive coverage of all key topics including security principles in software development, threat modeling, secure coding practices, authentication and authorization, cryptography implementation, API security, vulnerability assessment, risk management, compliance frameworks (OWASP, NIST), and secure software development lifecycle (SDLC) methodologies. Each answer is verified and aligned with current WGU course objectives and competency requirements. Perfect for OA and Pre-Assessment success. With our Pass Guarantee, you can confidently achieve your A+ grade. Download your complete WGU D487 Secure Software Design guide instantly!

Meer zien Lees minder
Instelling
WGU D487 SECURE SW DESIGN OA
Vak
WGU D487 SECURE SW DESIGN OA

Voorbeeld van de inhoud

1



WGU D487 SECURE SOFTWARE DESIGN 2026/2027 | OA &
Pre-Assessment Exam | Complete Verified Answers | A+
Grade | Pass Guaranteed


[Section 1: Secure Software Design Principles & Threat Modeling (Q1-18)]

Q1. A software system is designed so that if a component fails, it defaults to a state
where no unauthorized access is possible. Which secure design principle is being
applied?

A. Least privilege
B. Defense in depth
C. Fail securely [CORRECT]
D. Open design

Rationale: Fail secure means the system defaults to a secure state when failures
occur. Least privilege limits access rights, defense in depth uses multiple layers of
security, and open design means security does not depend on secrecy of the design.

Correct Answer: C

Q2. A banking application requires both a password and a hardware token for high-
value transactions. Which secure design principle does this demonstrate?

A. Separation of privilege [CORRECT]
B. Least common mechanism
C. Economy of mechanism
D. Psychological acceptability

Rationale: Separation of privilege requires multiple conditions to complete a sensitive
operation (e.g., password + hardware token). Least common mechanism avoids
shared resources, economy of mechanism keeps design simple, and psychological
acceptability ensures security is user-friendly.

Correct Answer: A

Q3. In threat modeling, an attacker is able to modify the contents of a database
record without authorization. Which STRIDE threat category does this represent?

,2



A. Spoofing
B. Tampering [CORRECT]
C. Repudiation
D. Information Disclosure

Rationale: Tampering involves unauthorized modification of data or systems.
Spoofing is impersonation, repudiation is denying an action, and information
disclosure is unauthorized data access. Database record modification is the classic
definition of tampering.

Correct Answer: B

Q4. A web application logs all user actions including timestamps, user IDs, and IP
addresses but does not protect the log files from deletion. Which STRIDE threat
category is present?

A. Spoofing
B. Tampering [CORRECT]
C. Denial of Service
D. Elevation of Privilege

Rationale: Unprotected log files susceptible to deletion represent tampering
(unauthorized modification/deletion of data). While this could also enable
repudiation, the immediate threat is tampering of the audit trail. Spoofing involves
identity, DoS involves availability, and elevation involves privilege escalation.

Correct Answer: B

Q5. A threat modeler assigns a risk score to a SQL injection vulnerability using the
DREAD model. The scores are: Damage 9, Reproducibility 8, Exploitability 7, Affected
Users 9, Discoverability 8. What is the calculated DREAD score?

A. 8.0
B. 8.2 [CORRECT]
C. 7.5
D. 9.0

Rationale: DREAD score = (Damage + Reproducibility + Exploitability + Affected
Users + Discoverability) / 5 = (9 + 8 + 7 + 9 + 8) / 5 = = 8.2. The formula
averages all five components on a 1-10 scale.

,3



Correct Answer: B

Q6. A development team is performing threat modeling on a new e-commerce
application. They identify all external interfaces, data entry points, and trust
boundaries. Which threat modeling methodology focuses on this structured
approach with data flow diagrams?

A. PASTA
B. STRIDE
C. Microsoft SDL Threat Modeling (using DFDs) [CORRECT]
D. Trike

Rationale: The Microsoft SDL approach uses data flow diagrams (DFDs) to identify
system components, data flows, and trust boundaries, then applies STRIDE to identify
threats. PASTA is risk-centric, STRIDE is a threat taxonomy (not a methodology), and
Trike focuses on asset-centric risk assessment.

Correct Answer: C

Q7. A system is designed so that no single user can complete a critical financial
transaction alone—two authorized users must approve it. Which principle is being
applied?

A. Least privilege
B. Separation of privilege [CORRECT]
C. Defense in depth
D. Complete mediation

Rationale: Separation of privilege (also called separation of duties) requires multiple
conditions or persons to complete a sensitive operation. Least privilege limits
individual access, defense in depth uses multiple security layers, and complete
mediation ensures every access is checked.

Correct Answer: B

Q8. An application uses a complex, proprietary encryption algorithm that the
development team believes is secure because its design is secret. Which principle is
being violated?

A. Open design [CORRECT]
B. Economy of mechanism

, 4



C. Fail securely
D. Least common mechanism

Rationale: Open design states that security should not depend on the secrecy of the
design or implementation. "Security through obscurity" violates this principle.
Economy of mechanism advocates simplicity, fail securely addresses failure states,
and least common mechanism avoids shared resources.

Correct Answer: A

Q9. In the PASTA threat modeling methodology, which phase involves mapping
identified threats to business objectives and technical scope?

A. Phase 1: Definition of objectives
B. Phase 2: Definition of technical scope
C. Phase 3: Application decomposition
D. Phase 4: Threat analysis [CORRECT]

Rationale: PASTA Phase 4 (Threat Analysis) maps threats to business objectives and
technical scope using threat libraries and attack trees. Phase 1 defines objectives,
Phase 2 defines scope, and Phase 3 decomposes the application into components
and data flows.

Correct Answer: D

Q10. A system validates every access request to protected resources, regardless of
whether the same user previously accessed the resource moments ago. Which
principle is being applied?

A. Complete mediation [CORRECT]
B. Least privilege
C. Separation of privilege
D. Defense in depth

Rationale: Complete mediation requires that every access to every object be checked
for authority. Caching previous authorization decisions would violate this principle.
Least privilege limits rights, separation of privilege requires multiple conditions, and
defense in depth uses multiple layers.

Correct Answer: A

Geschreven voor

Instelling
WGU D487 SECURE SW DESIGN OA
Vak
WGU D487 SECURE SW DESIGN OA

Documentinformatie

Geüpload op
4 juni 2026
Aantal pagina's
33
Geschreven in
2025/2026
Type
Tentamen (uitwerkingen)
Bevat
Vragen en antwoorden

Onderwerpen

$20.50
Krijg toegang tot het volledige document:

Verkeerd document? Gratis ruilen Binnen 14 dagen na aankoop en voor het downloaden kun je een ander document kiezen. Je kunt het bedrag gewoon opnieuw besteden.
Geschreven door studenten die geslaagd zijn
Direct beschikbaar na je betaling
Online lezen of als PDF


Ook beschikbaar in voordeelbundel

Maak kennis met de verkoper

Seller avatar
De reputatie van een verkoper is gebaseerd op het aantal documenten dat iemand tegen betaling verkocht heeft en de beoordelingen die voor die items ontvangen zijn. Er zijn drie niveau’s te onderscheiden: brons, zilver en goud. Hoe beter de reputatie, hoe meer de kwaliteit van zijn of haar werk te vertrouwen is.
NURSEEXAMITY South University
Volgen Je moet ingelogd zijn om studenten of vakken te kunnen volgen
Verkocht
458
Lid sinds
4 jaar
Aantal volgers
272
Documenten
5766
Laatst verkocht
3 uur geleden
Writing and Academics (proctoredbypassexam at gmail dot com)

I offer a full range of online academic services aimed to students who need support with their academics. Whether you need tutoring, help with homework, paper writing, or proofreading, I am here to help you reach your academic goals. My experience spans a wide range of disciplines. I provide online sessions using the Google Workplace. If you have an interest in working with me, please contact me for a free consultation to explore your requirements and how I can help you in your academic path. I am pleased to help you achieve in your academics and attain your full potential.

Lees meer Lees minder
3.4

88 beoordelingen

5
30
4
15
3
22
2
2
1
19

Recent door jou bekeken

Waarom studenten kiezen voor Stuvia

Gemaakt door medestudenten, geverifieerd door reviews

Kwaliteit die je kunt vertrouwen: geschreven door studenten die slaagden en beoordeeld door anderen die dit document gebruikten.

Niet tevreden? Kies een ander document

Geen zorgen! Je kunt voor hetzelfde geld direct een ander document kiezen dat beter past bij wat je zoekt.

Betaal zoals je wilt, start meteen met leren

Geen abonnement, geen verplichtingen. Betaal zoals je gewend bent via iDeal of creditcard en download je PDF-document meteen.

Student with book image

“Gekocht, gedownload en geslaagd. Zo makkelijk kan het dus zijn.”

Alisha Student

Bezig met je bronvermelding?

Maak nauwkeurige citaten in APA, MLA en Harvard met onze gratis bronnengenerator.

Bezig met je bronvermelding?

Veelgestelde vragen