z z z z z z
DESIGN EXAM LATEST 2024 ACTUAL EXAM 400 QUESTIONS A
z z z z z z z z
ND CORRECT DETAILED ANSWERS WITH RATIONALES (VERIF
z z z z z z
IED ANSWERS) |ALREADY GRADED A+
z z z z
Whatziszazstepzforzconstructingzazthreatzmodelzforzazprojectzwhenzusingzpracticalzriskzanalysis?
AzAlignzyourzbusinesszgoals
BzApplyzengineeringzmethods
CzEstimatezprobabilityzofzprojectztime
DzMakezazlistzofzwhatzyouzareztryingztozprotectz-zANSWER-D
Whichzcyberzthreatszareztypicallyzsurgicalzbyznature,zhavezhighlyzspecificztargeting,zandzareztechnological
lyzsophisticated?
AzTacticalzattacks
BzCriminalzattacks
CzStrategiczattacks
DzUser-specificzattacksz-zANSWER-A
Whichztypezofzcyberattackszarezoftenzintendedztozelevatezawarenesszofzaztopic?
AzCyberwarfare
BzTacticalzattacks
CzUser-specificzattacks
DzSociopoliticalzattacksz-zANSWER-D
Whatztypezofzattackzlockszazuser'szdesktopzandzthenzrequireszazpaymentztozunlockzit?
AzPhishing
, WGU MASTER'S COURSE C706 - SECURE SOFTWARE
z z z z z z
DESIGN EXAM LATEST 2024 ACTUAL EXAM 400 QUESTIONS A
z z z z z z z z
ND CORRECT DETAILED ANSWERS WITH RATIONALES (VERIF
z z z z z z
IED ANSWERS) |ALREADY GRADED A+
z z z z
BzKeylogger
CzRansomware
DzDenial-of-servicez-zANSWER-C
WhatziszazcountermeasurezagainstzvariouszformszofzXMLzandzXMLzpathzinjectionzattacks?
AzXMLznamezwrapping
BzXMLzunicodezencoding
CzXMLzattributezescaping
DzXMLzdistinguishedznamezescapingz-zANSWER-C
WhichzcountermeasureziszusedztozmitigatezSQLzinjectionzattacks?
AzSQLzFirewall
BzProjectedzbijection
CzQueryzparameterization
DzProgressivezColdFusionz-zANSWER-C
Whatziszanzappropriatezcountermeasureztozanzescalationzofzprivilegezattack?
AzEnforcingzstrongzpasswordzpolicies
BzUsingzstandardzencryptionzalgorithmszandzcorrectzkeyzsizes
CzEnablingzthezauditingzandzloggingzofzallzadministrationzactivities
DzRestrictingzaccessztozspecificzoperationszthroughzrole-basedzaccesszcontrolsz-zANSWER-D
, WGU MASTER'S COURSE C706 - SECURE SOFTWARE
z z z z z z
DESIGN EXAM LATEST 2024 ACTUAL EXAM 400 QUESTIONS A
z z z z z z z z
ND CORRECT DETAILED ANSWERS WITH RATIONALES (VERIF
z z z z z z
IED ANSWERS) |ALREADY GRADED A+
z z z z
Whichzconfigurationzmanagementzsecurityzcountermeasurezimplementszleastzprivilegezaccesszcontrol?
AzFollowingzstrongzpasswordzpoliciesztozrestrictzaccess
BzRestrictingzfilezaccessztozuserszbasedzonzauthorization
CzAvoidingzclearztextzformatzforzcredentialszandzsensitivezdata
DzUsingzAESz256zencryptionzforzcommunicationszofzazsensitiveznaturez-zANSWER-B
Whichzphasezofzthezsoftwarezdevelopmentzlifezcyclez(SDL/SDLC)zwouldzbezusedztozdeterminezthezmini
mumzsetzofzprivilegeszrequiredztozperformztheztargetedztaskzandzrestrictzthezuserztozazdomainzwithzthos
ezprivileges?
AzDesign
BzDeploy
CzDevelopment
DzImplementationz-zANSWER-A
Whichzleastzprivilegezmethodziszmorezgranularzinzscopezandzgrantszspecificzprocesseszonlyzthezprivilege
sznecessaryztozperformzcertainzrequiredzfunctions,zinsteadzofzgrantingzthemzunrestrictedzaccessztozthezs
ystem?
AzEntitlementzprivilege
BzSeparationzofzprivilege
CzAggregationzofzprivileges
DzSegregationzofzresponsibilitiesz-zANSWER-B
Whyzdoeszprivilegezcreepzposezazpotentialzsecurityzrisk?
, WGU MASTER'S COURSE C706 - SECURE SOFTWARE
z z z z z z
DESIGN EXAM LATEST 2024 ACTUAL EXAM 400 QUESTIONS A
z z z z z z z z
ND CORRECT DETAILED ANSWERS WITH RATIONALES (VERIF
z z z z z z
IED ANSWERS) |ALREADY GRADED A+
z z z z
AzUserzprivilegeszdoznotzmatchztheirzjobzrole.
BzWithzmorezprivileges,ztherezarezmorezresponsibilities.
CzAuditingzwillzshowzazmismatchzbetweenzindividualzresponsibilitieszandztheirzaccesszrights.
DzUserszhavezmorezprivilegeszthanztheyzneedzandzmayzperformzactionszoutsideztheirzjobzdescription.z-
zANSWER-D
Azsystemzdeveloperziszimplementingzaznewzsaleszsystem.zThezsystemzdeveloperziszconcernedzthatzunaut
horizedzindividualszmayzbezableztozviewzsensitivezcustomerzfinancialzdata.
Whichzfamilyzofznonfunctionalzrequirementszshouldzbezconsideredzaszpartzofzthezacceptancezcriteria?
AzIntegrity
BzAvailability
CzNonrepudition
DzConfidentialityz-zANSWER-D
Azprojectzmanagerziszgivenztheztaskztozcomezupzwithznonfunctionalzacceptancezcriteriazrequirementszfo
rzbusinesszownerszaszpartzofzazprojectzdelivery.
Whichznonfunctionalzrequirementzshouldzbezappliedztozthezacceptancezcriteria?
AzGivezsearchzoptionsztozusers
BzEvaluateztestzexecutionzresults
CzDividezuserszintozgroupszandzgivezthemzseparatezrights
DzDevelopzsoftwarezthatzkeepszdownwardzcompatibilityzintactz-zANSWER-B