g g g g g
SOFTWARE DESIGN EXAM LATEST 2024 ACTUAL
g g g g g g
EXAM 300 QUESTIONS AND CORRECT DETAILED
g g g g g g
ANSWERS WITH RATIONALES (VERIFIED ANSW
g g g g
ERS) |ALREADY GRADED A+
g g g
Whichgphasegofgthegsoftwaregdevelopmentglifegcycleg(SDL/SDLC)gwou
ldgbegusedgtogdeterminegthegminimumgsetgofgprivilegesgrequiredgtogperfo
rmgthegtargetedgtaskgandgrestrictgthegusergtogagdomaingwithgthosegprivileg
es?
AgDesign
BgDeploy
CgDevelopment
DgImplementationg-g...ANSWER..A
Whichgleastgprivilegegmethodgisgmoreggranulargingscopegandggrantsgspec
ificgprocessesgonlygthegprivilegesgnecessarygtogperformgcertaingrequiredg
functions,ginsteadgofggrantinggthemgunrestrictedgaccessgtogthegsystem?
AgEntitlementgprivilege
BgSeparationgofgprivilege
CgAggregationgofgprivileges
DgSegregationgofgresponsibilitiesg-g...ANSWER..B
Whygdoesgprivilegegcreepgposegagpotentialgsecuritygrisk?
AgUsergprivilegesgdognotgmatchgtheirgjobgrole.
BgWithgmoregprivileges,gtheregaregmoregresponsibilities.
CgAuditinggwillgshowgagmismatchgbetweengindividualgresponsibilitiesga
ndgtheirgaccessgrights.
,DgUsersghavegmoregprivilegesgthangtheygneedgandgmaygperformgactionsg
outsidegtheirgjobgdescription.g-g...ANSWER..D
Agsystemgdevelopergisgimplementinggagnewgsalesgsystem.gThegsystemgd
evelopergisgconcernedgthatgunauthorizedgindividualsgmaygbegablegtogvie
wgsensitivegcustomergfinancialgdata.
Whichgfamilygofgnonfunctionalgrequirementsgshouldgbegconsideredgasgp
artgofgthegacceptancegcriteria?
AgIntegrity
BgAvailability
CgNonrepudition
DgConfidentialityg-g...ANSWER..D
Agprojectgmanagergisggivengthegtaskgtogcomegupgwithgnonfunctionalgacce
ptancegcriteriagrequirementsgforgbusinessgownersgasgpartgofgagprojectgdel
ivery.
Whichgnonfunctionalgrequirementgshouldgbegappliedgtogthegacceptanceg
criteria?
AgGivegsearchgoptionsgtogusers
BgEvaluategtestgexecutiongresults
CgDividegusersgintoggroupsgandggivegthemgseparategrights
DgDevelopgsoftwaregthatgkeepsgdownwardgcompatibilitygintactg-
...ANSWER..B
Agusergwasggivengagtaskgtogidentifygagnonfunctionalgacceptancegcriteria.
Whichgnonfunctionalgrequirementgshouldgbegappliedgtogthegacceptancegc
riteria?
AgEncryptiongusedgduringgdatagtransfer
BgReviewgofgthegmostgrecentgtestgresults
CgSoftwaregdevelopedgkeepinggdownwardgcompatibilitygintact
,DgUsersgdividedgintoggroupsgandgtheggroupsggivengseparategrightsg-
...ANSWER..B
Whichgtechniquegcangbegusedgbygangattackergtogcompromisegpasswordg
securitygwhengagpasswordgsuchgasg"123456"gisgusedgbygangorganization
?
AgDenial-of-servicegattack
BgBrute-forcegattack
CgBlindgSQLginjection
DgBlindgXPathginjectiong-g...ANSWER..B
Whichgtypegofgpasswordgattackgtestsgforgeverygpossiblegvaluegofgagparam
eter?
AgPhishing
BgBrutegforce
CgDNSgpoisoning
DgCachegpoisoningg-g...ANSWER..B
Whichgtypegofgattackgallowsgthegcompletegdisclosuregorgdestructiongofg
allgdatagongagsystemgandgallowsgattackersgtogspoofgidentity,gtampergwit
hgexistinggdata,gandgcausegrepudiationgissuesgsuchgasgvoidinggtransacti
onsgorgchanginggbalances?
AgSQLginjection
BgCodeginjection
CgCommandginjection
DgSpecialgelementginjectiong-g...ANSWER..A
Whichgthreatgusesgmalwaregthatgtricksgusersgintogbelievinggthatgtheregisg
nogwaygoutgforgthemgexceptgtogpaygtoggetgridgofgagnuisance?
AgScriptgkiddies
BgInsidergthreats
CgRansomware
DgBitcoingmalwareg-g...ANSWER..C
, Whichgtypegofgapplicationgattackgisgusedgtogharvestgandgstealgsensitivegin
formation?
AgWhaling
BgRemotegaccessgtool
CgMaliciousgfilegexecution
DgAdvancedgpersistentgthreatg-g...ANSWER..B
Whichgtypegofgapplicationgattackgisgcommonlygwagedgthroughgthegusego
fgrootkits?
AgBackdoor
BgTimegofgcheck
CgRainbowgtable
DgEscalationgofgprivilegeg-g...ANSWER..D
Whichgattackgaimsgtogmakegwebgservicegunavailablegorgunusable?
AgSpoofing
BgTampering
CgRepudiation
DgDenial-of-serviceg-g...ANSWER..D
Agcompanygisgdevelopinggagnewgsoftwaregapplicationgthatgrequiresguser
sgtogloggingusinggagusernamegandgpassword.gThegcompanygneedsgtogimpl
ementgagsecuritygcontrolgthatgisgeffectivegatgpreventinggspoofinggduringg
theglog-ingprocess.
Whichgsecuritygcontrolgisgeffectivegatgpreventinggthisgthreatgaction?
AgIntegrity
BgAuthorization
CgAuthentication
DgConfidentialityg-g...ANSWER..C