2025 ACTUAL EXAM 2 VERSIONS (VERSION A AND B)
COMPLETE ACCURATE EXAM QUESTIONS WITH
DETAILED VERIFIED ANSWERS (100% CORRECT
ANSWERS) /ALREADY GRADED A+
BSIMM
- ANSWER-Building Security In Maturity Model
Studies real-world software security initiatives for benchmarking
SAMM
- ANSWER-Software Assurance Maturity Model
BSIMM Four Domains –
ANSWER-🏛️ Governance: Strategy, compliance, training programs
Intelligence: Attack models, security features, standards research
🔨 SSDL Touchpoints: Hands-on security activities (code review, testing)
🚀 Deployment: Configuration management, vulnerability management
STRIDE Threat Modeling
- ANSWER-Spoofing: Identity impersonation attacks
Tampering: Unauthorized data modification
Repudiation: Denial of performed actions
Information Disclosure: Unauthorized data access
Denial of Service: Service availability attacks
,WGU D487 SECURE SW DESIGN PRACTICE EXAM
2025 ACTUAL EXAM 2 VERSIONS (VERSION A AND B)
COMPLETE ACCURATE EXAM QUESTIONS WITH
DETAILED VERIFIED ANSWERS (100% CORRECT
ANSWERS) /ALREADY GRADED A+
Elevation of Privilege: Unauthorized access escalation
Purpose - Threat Categorization
STRIDE-per-element
- ANSWER-Analyze each individual component/object
STRIDE-per-process:
- ANSWER-Focus only on processes
STRIDE-per-trust-boundary
- ANSWER-Analyze security boundary crossings
STRIDE-per-interaction
- ANSWER-Focus on data flows between components
DREAD Stages –
ANSWER-Damage: Potential impact severity
Reproducibility: How easily attack can be repeated
Exploitability: Difficulty of executing the attack
Affected users: Scope and number of impacted users
, WGU D487 SECURE SW DESIGN PRACTICE EXAM
2025 ACTUAL EXAM 2 VERSIONS (VERSION A AND B)
COMPLETE ACCURATE EXAM QUESTIONS WITH
DETAILED VERIFIED ANSWERS (100% CORRECT
ANSWERS) /ALREADY GRADED A+
Discoverability: How easy vulnerability is to find
DREAD Scoring System –
ANSWER-Each Stage gets 1-3 Points
13-15 points = High Risk
8-12 points = Medium Risk
5-7 points = Low Risk
PASTA
- ANSWER-Process for Attack Simulation and Threat Analysis
PASTA Seven Stages –
ANSWER-Define Objectives - Business and security requirements
Define Technical Scope - Application boundaries and components
Application Decomposition - Break down architecture and data flows
Threat Analysis - Identify potential threats and attack vectors
Vulnerability and Weakness Analysis - Design flaw analysis occurs here
Attack Modeling - Develop specific attack scenarios
Risk and Impact Analysis - Evaluate business impact and likelihood