Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Exam (elaborations)

WGU D487 SECURE SOFTWARE DESIGN ACTUAL EXAM QUESTIONS AND CORRECT ANSWERS RATED A+

Rating
-
Sold
-
Pages
73
Grade
A+
Uploaded on
05-06-2025
Written in
2024/2025

WGU D487 SECURE SOFTWARE DESIGN ACTUAL EXAM QUESTIONS AND CORRECT ANSWERS RATED A+

Institution
WGU D487 SECURE SOFTWARE DESIGN
Course
WGU D487 SECURE SOFTWARE DESIGN

Content preview

WGU D487 SECURE SOFTWARE DESIGN
ACTUAL EXAM QUESTIONS AND
CORRECT ANSWERS RATED A+




In the agile model, projects are divided into small incremental builds that provide working
software at the end of each iteration and adds value to business."

"In Scrum methodology, who is responsible for making decisions on the requirements?
Scrum Team
Product Owner
ScrumMaster
Technical Lead - CORRECT ANSWER=> Product Owner

The Product Owner is responsible for requirements/backlog items and prioritizing them."

"What is the reason software security teams host discovery meetings with stakeholders early in
the development life cycle?
To determine how much budget is available for new security tools
To meet the development team
To refactor functional requirements to ensure security is included
To ensure that security is built into the product from the start - CORRECT ANSWER=> To ensure
that security is built into the product from the start

To correctly and cost-effectively introduce security into the software development life cycle, it
needs to be done early."

"Which software methodology resembles an assembly-line approach?
V-model

Page | 1

,Agile model
Iterative model
Waterfall model - CORRECT ANSWER=> Waterfall model

Waterfall model is a continuous software development model in which the development steps
flow steadily downwards."

"Which software methodology approach provides faster time to market and higher business
value?
Iterative model
Waterfall model
V-model
Agile model - CORRECT ANSWER=> Agile model



"Why should a security team provide documented certification requirements during the
software assessment phase?
Certification is required if the organization wants to move to the cloud.
Depending on the environment in which the product resides, certifications may be required by
corporate or government entities before the software can be released to customers.
By ensuring software products are certified, the organization is protected from future litigation.
By ensuring all developers have security certifications before writing any code, teams can forego
discovery sessions. - CORRECT ANSWER=> Depending on the environment in which the product
resides, certifications may be required by corporate or government entities before the software
can be released to customers.

Any new product may need to be certified based on the data it stores, the frameworks it uses,
or the domain in which it resides. Those certification requirements need to be analyzed and
documented early in the development life cycle."

"What are two items that should be included in the privacy impact assessment plan regardless
of which methodology is used?Choose 2 answers.
Required process steps
Technologies and techniques
SDL project outline
Threat modeling
Post-implementation signoffs - CORRECT ANSWER=> Required process steps
Technologies and techniques

Page | 2

,"Required process steps" is correct. Required process steps explain in more detail which
requirements are relevant to developers, detailing what types of data are considered sensitive
and how they need to be protected.
"Technologies and techniques" is correct. Technologies and techniques detail techniques for
meeting legislative requirements in five categories: Confidentiality, Integrity, Availability,
Auditing and Logging, and Authentication."

"What are the goals of each SDL deliverable?
Select one of these options for each deliverable:
-Estimate the actual cost of the product
-Identify dependence on unmanaged software
-Map security activities to the development schedule
-Guide security activities to protect the product from vulnerabilities

Product risk profile

SDL project outline

Threat profile

List of third-party software - CORRECT ANSWER=> Estimate the actual cost of the product
Map security activities to the development schedule
Guide security activities to protect the product from vulnerabilities
Identify dependence on unmanaged software



The product risk profile helps management see the actual cost of a product.
The SDL project outline maps security activities to the development schedule.
A threat profile guides the security team on how to protect the product from threats.
The third-party software list identifies all components the product is using that are managed
outside the organization."

"What is a threat action that is designed to illegally access and use another person's
credentials?
Tampering
Spoofing
Elevation of privilege

Page | 3

, Information disclosure - CORRECT ANSWER=> Spoofing

Spoofing is a threat action that occurs when the cyber criminal acts as a trusted device to get
you to relay secure information."

"What are two steps of the threat modeling process?Choose 2 answers.
Survey the application
Decompose the application
Redesign the process to eliminate the threat
Transfer the risk
Identify business requirements - CORRECT ANSWER=> Survey the application
Decompose the application

"Survey the application" is correct. Surveying the application is a way to gain knowledge of how
the product works by reading product documentation and interviewing the development team.
"Decompose the application" is correct. Decomposing the application can be done by doing a
deep dive into the code and understanding how it works behind the scenes."

"What do the "A" and the first "D" in the DREAD acronym represent?Choose 2 answers.
Damage
Affected users
Denial of service
Authentication - CORRECT ANSWER=> Damage
Affected users

"Damage" is correct. Damage represents the first 'D' in DREAD and measures how much
damage will be caused if the threat exploit occurs.
"Affected users" is correct. Affected users represents the 'A' in DREAD and measures how many
users will be affected."

"Which shape indicates each type of flow diagram element?
Select an option for each element:
-Two parallel horizontal lines
-Solid line with an arrow.
-Rectangle
-Dashed line

External elements

Page | 4

Written for

Institution
WGU D487 SECURE SOFTWARE DESIGN
Course
WGU D487 SECURE SOFTWARE DESIGN

Document information

Uploaded on
June 5, 2025
Number of pages
73
Written in
2024/2025
Type
Exam (elaborations)
Contains
Questions & answers

Subjects

$30.49
Get access to the full document:

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF


Also available in package deal

Get to know the seller

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
Chareiezekiel Chamberlain College Of Nursing
Follow You need to be logged in order to follow users or courses
Sold
100
Member since
2 year
Number of followers
22
Documents
3035
Last sold
3 weeks ago

✅ Trusted by Top Nursing Students Nationwide My mission is to be your LIGHT in the dark. If you're worried or having trouble in nursing school, I really want my notes to be your guide! I know they have helped countless others get through and that's all I want for YOU! Stay with me and you will find everything you need to study and pass any tests, quizzes and exams!

4.9

996 reviews

5
947
4
19
3
18
2
3
1
9

Recently viewed by you

Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions