Exam Actual Exam - Exam | Actual Exam (Version A & B) | 100% Corr...

WGU EXAMS Sep 4, 2025
Loading...

Loading document viewer...

Page 0 of 0

Document Text

WGU D487 – Secure Software Design Exam | 2025/2026 Actual Exam (Version A & B) | 100% Correct Verified Answers | Graded A+

Section 1: Introduction

This comprehensive guide includes both Version A and Version B of the WGU D487 Secure Software Design Exam, tailored to the 2025/2026 certification cycle. It contains detailed, accurate questions and verified answers for each version, reflecting the most current curriculum standards in secure software architecture, threat mitigation, SDLC integration, and compliance frameworks. The content is designed to help students prepare confidently and succeed with distinction—each question is paired with a brief rationale for clarity and mastery.

Section 2: Exam Content and Responses

Version A

1 Question: What is the primary goal of secure software design?

  • Maximize software performance
  • Protect applications from security threats
  • Reduce development time
  • Enhance user interface

Correct Answer: B. Protect applications from security threats

Rationale: Secure design focuses on mitigating vulnerabilities throughout the SDLC.

2 Question: Which SDLC phase is most critical for integrating security?

  • Testing
  • Requirements gathering
  • Deployment
  • Maintenance

Correct Answer: B. Requirements gathering

Rationale: Early integration in requirements ensures security is built-in, per NIST guidelines.

3 Question: What is the purpose of threat modeling in secure software design?

  • Optimize code efficiency
  • Identify potential security risks
  • Increase system uptime
  • Reduce hardware costs

Correct Answer: B. Identify potential security risks

Rationale: Threat modeling, as per OWASP, maps risks to mitigate them proactively.

4 Question: Which principle advocates minimizing attack surfaces?

  • Least privilege 1 / 4
  • Defense in depth
  • Secure by default
  • Fail secure

Correct Answer: C. Secure by default

Rationale: Secure by default reduces exposed vulnerabilities from the start.

5 Question: What does input validation prevent?

  • System crashes
  • Injection attacks
  • Network latency
  • Data storage issues

Correct Answer: B. Injection attacks

Rationale: Validates data to block malicious inputs, aligning with OWASP Top Ten.

6 Question: Which technique is used to encrypt data at rest?

A. TLS

B. AES

C. HTTPS

D. SHA-256

Correct Answer: B. AES

Rationale: AES is a symmetric encryption standard for data at rest.

  • Question: What is a key benefit of using a secure development lifecycle (SDL)?
  • Faster deployment
  • Reduced security vulnerabilities
  • Lower training costs
  • Simplified testing

Correct Answer: B. Reduced security vulnerabilities

Rationale: SDL embeds security practices to minimize flaws, per Microsoft SDL.

8 Question: Which OWASP Top Ten risk involves exposing sensitive data?

  • Broken authentication
  • Security misconfiguration
  • Insecure deserialization
  • Sensitive data exposure

Correct Answer: D. Sensitive data exposure

Rationale: This risk highlights improper data protection.

9 Question: What is the purpose of a code review in secure software design?

  • Improve performance
  • Detect security flaws
  • Increase user access
  • Reduce memory usage

Correct Answer: B. Detect security flaws

Rationale: Reviews identify vulnerabilities before deployment.

10 Question: Which compliance framework addresses software security?

A. PCI DSS

B. ISO 27001

C. HIPAA 2 / 4

D. GDPR

Correct Answer: A. PCI DSS

Rationale: PCI DSS includes specific software security requirements.

11 Question: What does the principle of least privilege enforce?

  • Full access for all users
  • Minimal necessary permissions
  • Unlimited resource use
  • Open network access

Correct Answer: B. Minimal necessary permissions

Rationale: Limits access to reduce potential damage.

12 Question: Which tool is commonly used for static code analysis?

  • Wireshark
  • SonarQube
  • Nmap
  • Metasploit

Correct Answer: B. SonarQube

Rationale: Analyzes code without execution to find vulnerabilities.

13 Question: What is a common vulnerability in web applications?

  • Cross-site scripting (XSS)
  • High CPU usage
  • Slow network speed
  • Large file sizes

Correct Answer: A. Cross-site scripting (XSS)

Rationale: XSS injects scripts, per OWASP Top Ten.

14 Question: Which technique mitigates buffer overflow attacks?

  • Input sanitization
  • Data compression
  • Network segmentation
  • User authentication

Correct Answer: A. Input sanitization

Rationale: Prevents excessive data input, a key defense.

15 Question: What is the purpose of a security regression test?

  • Improve UI design
  • Verify fixes don’t reintroduce vulnerabilities
  • Increase processing speed
  • Reduce database size

Correct Answer: B. Verify fixes don’t reintroduce vulnerabilities

Rationale: Ensures security stability post-update.

16 Question: Which protocol secures API communications?

A. HTTP

  • OAuth

C. FTP

D. SMTP 3 / 4

Correct Answer: B. OAuth

Rationale: OAuth provides secure authorization for APIs.

17 Question: What does defense in depth involve?

  • Single security layer
  • Multiple overlapping controls
  • Reduced monitoring
  • Open access policies

Correct Answer: B. Multiple overlapping controls

Rationale: Layers enhance overall security.

18 Question: Which metric tracks the number of vulnerabilities found?

  • Uptime percentage
  • Vulnerability density
  • Response time
  • Data throughput

Correct Answer: B. Vulnerability density

Rationale: Measures security quality.

19 Question: What is a key benefit of using container security?

  • Reduced deployment time
  • Isolated application environments
  • Simplified user access
  • Lower hardware costs

Correct Answer: B. Isolated application environments

Rationale: Isolation limits breach impact.

20 Question: Which practice prevents SQL injection?

  • Parameterized queries
  • Open database access
  • Unvalidated inputs
  • Direct SQL execution

Correct Answer: A. Parameterized queries

Rationale: Prevents malicious SQL input.

21 Question: What is the purpose of a security champion program?

  • Reduce development costs
  • Promote security awareness in teams
  • Increase system uptime
  • Simplify testing

Correct Answer: B. Promote security awareness in teams

Rationale: Champions embed security culture.

22 Question: Which standard guides secure coding practices?

A. ISO 9001

  • CERT Secure Coding

C. PCI DSS

D. GDPR

Correct Answer: B. CERT Secure Coding

Rationale: Provides coding security standards.

  • / 4

Download Document

Buy This Document

$30.00 One-time purchase
Buy Now
  • Full access to this document
  • Download anytime
  • No expiration

Document Information

Category: WGU EXAMS
Added: Sep 4, 2025
Description:

WGU D487 – Secure Software Design Exam | Actual Exam (Version A & B) | 100% Correct Verified Answers | Graded A+ Section 1: Introduction This comprehensive guide includes both Version A and Versi...

Get this document $30.00