Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Exam (elaborations)

WGU D487 OA EXAM 200 QUESTIONS & CORRECT ANSWERS LATEST 2025

Rating
-
Sold
1
Pages
35
Grade
A+
Uploaded on
19-03-2025
Written in
2024/2025

WGU D487 OA EXAM 200 QUESTIONS & CORRECT ANSWERS LATEST 2025

Institution
WGU D487 OA
Course
WGU D487 OA

Content preview

WGU D487 OA EXAM 200 QUESTIONS & CORRECT
ANSWERS LATEST 2025




Privacy Compliance Report
The _________ report should provide progress against privacy requirements
provided in earlier phases. Any outstanding requirement should be implemented
as soon as possible. It is also prudent to assess any changes in laws/regulations to
identify (and put on a roadmap) any new requirements. A4 D&D
Security Testing Reports
A findings summary should be prepared for each type of security testing: manual
code review, static analysis, dynamic analysis, penetration testing, and fuzzing.
The reports should provide the type and number of issues identified and any
consistent theme that can be derived from the findings. A4 D&D
Remediation Report
A ____ report/dashboard should be prepared and updated regularly from this
stage. The purpose of this report is to showcase the security posture and risk of
the product at a technical level. A4 D&D
Security Assessment
What are the key activities in the Security Assessment phase of SDL?
SDL Phase 1 (A1) = SDLC 1 Concept

Software security team is looped in early
Security team hosts a discovery meeting
Software security team discusses project plan
States what further work will be done
Privacy Impact Assessment (PIA) plan is created

,Architecture
What are the key activities in the Architecture phase of SDL?
SDL Phase 2 (A2) = SDLC 2 Planning

A2 Policy compliance analysis
SDL policy assessment and scoping
Threat modeling & architecture security analysis
Open-source selection
Privacy information gathering and analysis
Design & Development
What are the key activities in the Design & Development phase of SDL?
SDL Phase 3 (A3) = SDLC 3 Design & Development

A3 Policy compliance analysis
Security test plan composition
Static analysis updating
Threat modeling analysis & review
Privacy implementation assessment
Design & Development Cont.
What are the key activities in the Design & Development Cont. phase of SDL?
SDL Phase 4 (A4) = SDLC 4 Readiness

A4 Policy compliance analysis
Security test case execution
Static analysis
Fuzz testing
Privacy code review
Privacy validation and remediation
Ship
What are the key activities in the Ship phase of SDL?
SDL Phase 5 (A5) = SDLC 5 Release & Launch

,A5 Policy compliance analysis
Vulnerability scan
Penetration testing
Open-source licensing review
Final privacy review
What is the purpose of the Product risk profile deliverable in Security Assessment
(A1)?
To estimate the actual cost of the product.
What is the goal of the SDL project outline in Security Assessment (A1)?
To map SDL activities to the development schedule.
Why are Applicable laws and regulations important in Security Assessment (A1)?
To obtain formal sign-off from stakeholders on applicable laws.
What is the purpose of the Threat profile in Security Assessment (A1)?
To guide SDL activities to mitigate threats.
What is the goal of the Certification requirements deliverable in Security
Assessment (A1)?
To list requirements for product and operations certifications.
Why is maintaining a List of third-party software important in Security
Assessment (A1)?
To identify dependence on third-party software.
What is the purpose of the Metrics template in Security Assessment (A1)?
To establish a cadence for regular reporting to executives.
What is the purpose of defining Business requirements in A2 Architecture?
To establish software requirements, including Confidentiality, Integrity, and
Availability (CIA).
What are Threat modeling artifacts used for in A2 Architecture?

, They include data flow diagrams, elements, and threat listings to assess security
risks.
What is the goal of Architecture threat analysis in A2 Architecture?
To prioritize threats and risks based on a detailed threat analysis.
What is a Risk mitigation plan in A2 Architecture?
A plan to mitigate, accept, or tolerate risk within the system.
What does Policy compliance analysis ensure in A2 Architecture?
It ensures adherence to company policies and security regulations.
What is the purpose of Updated threat modeling artifacts in A3 Design &
Development?
To maintain data flow diagrams, elements, and threat listings for security analysis.
What does a Design security review focus on in A3 Design & Development?
It includes modifications to the design of software components based on security
assessments.
What is the purpose of Security test plans in A3 Design & Development?
To create a plan to mitigate, accept, or tolerate risk.
What does Updated policy compliance analysis ensure in A3 Design &
Development?
It ensures adherence to company policies.
What are Privacy implementation assessment results used for in A3 Design &
Development?
They provide recommendations from privacy assessments to improve
compliance.
What is the purpose of the Security test execution report in A4 Design &
Development?
To review progress against identified security test cases.

Written for

Institution
WGU D487 OA
Course
WGU D487 OA

Document information

Uploaded on
March 19, 2025
Number of pages
35
Written in
2024/2025
Type
Exam (elaborations)
Contains
Questions & answers

Subjects

$20.49
Get access to the full document:

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF


Also available in package deal

Get to know the seller

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
NurseSue Johns Hopkins University
Follow You need to be logged in order to follow users or courses
Sold
56
Member since
2 year
Number of followers
4
Documents
1185
Last sold
4 weeks ago

3.8

9 reviews

5
4
4
1
3
3
2
0
1
1

Recently viewed by you

Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions