Limited-Time Offer: Enjoy 50% Savings! Ends in 00h 00m 00s Coupon code: 50OFF
Skip to content

Free WGU Secure Software Design Secure-Software-Design Exam Questions

Page: 1 / 12 Total 118 questions

Want more questions? Get Premium Access.

Question 1

Which secure software design principle states that it is always safer to require agreement of more than one entity to make a decision?

Correct Answer: C. Separation of Privileges

Question 2

What is a best practice of secure coding?

Correct Answer: B. Session management
Explanation:

Session management is a core component of secure coding, which involves maintaining the state of a user's interaction with a system. Proper session management can help protect against various security vulnerabilities, such as session hijacking and session fixation attacks. It is essential for ensuring that user data is handled securely throughout an application's workflow.


Question 3

Features have been developed and fully tested, the production environment has been created, and leadership has approved the release of the new product. Technicians have scheduled a time and date to make the product available to customers.

Which phase of the software development lifecycle (SDLC) is being described?

Correct Answer: B. Deployment
Explanation:

The phase being described is the Deployment phase of the SDLC. This phase involves making the software available for use by customers after it has been developed, tested, and approved for release. It includes the installation of the software in the production environment, ensuring that all features are operational as intended, and obtaining formal approval from leadership to proceed with making the product available to end-users. The deployment phase is critical as it transitions the software from a development setting to a real-world operational environment.


SDLC Deployment Phase -- A Step by Step Guide1

Understanding the SDLC: Software Development Lifecycle Explained2

Question 4

Which concept is demonstrated when every module in a particular abstraction layer of a computing environment can only access the information and resources that are necessary for its legitimate purpose?

Correct Answer: B. Principle of Least Privilege

Question 5

Which software control test examines an application from a user perspective by providing a wide variety of input scenarios and inspecting the output?

Correct Answer: B. Black box
Explanation:

The software control test that examines an application from a user perspective by providing a wide variety of input scenarios and inspecting the output is known as black box testing. This testing method focuses on the functionality of the application rather than its internal structures or workings. Testers provide inputs and examine outputs without knowing how and where the inputs are worked upon. It's designed to test the system's external behavior.

Black box testing is used to verify that the system meets the requirements and behaves as expected in various scenarios, including edge cases and incorrect input data. It helps in identifying discrepancies between the system's actual functionality and its specified requirements.

This type of testing is applicable across various levels of software testing, including unit, integration, system, and acceptance testing. It is particularly useful for validating user stories and use cases during the software development process.

Since black box testing treats the software as a ''black box'', it does not require the tester to have knowledge of the programming languages or the system's implementation. This allows testers to objectively test the software's behavior and performance.


Question 6

Which threat modeling step assigns a score to discovered threats?

Correct Answer: A. Rate Threats

Question 7

In which step of the PASTA threat modeling methodology will the team capture infrastructure, application, and software dependencies?

Correct Answer: B. Define technical scope
Explanation:

The step of the PASTA threat modeling methodology where the team will capture infrastructure, application, and software dependencies is the Define technical scope step. This step involves detailing the technical elements of the project, which includes understanding and documenting the infrastructure, applications, and software dependencies that are critical to the system's operation and security.


Question 8

Which software-testing technique can be automated or semi-automated and provides invalid, unexpected, or random data to the inputs of a computer software program?

Correct Answer: A. Fuzzing
Explanation:

Fuzzing is an automated or semi-automated software testing technique that involves providing invalid, unexpected, or random data to the inputs of a computer program1. This process is designed to uncover coding errors, security vulnerabilities, and other potential issues within the software by observing how it behaves under unexpected or malformed inputs. Fuzzing is particularly effective because it can expose corner cases that have not been properly dealt with and can be used to test programs that take structured inputs, such as file formats or protocols2.


Question 9

A recent vulnerability scan uncovered an XML external entity (XXE) Haw that could allow attackers to return the contents of a system file by including a specific payload in an XML request.

How should the organization remediate this vulnerability?

Correct Answer: D. Ensure authentication cookies are encrypted
Explanation:

Security change management within the change management process involves ensuring that any changes, including updates or modifications to software, do not introduce new vulnerabilities and are in line with security policies. The question about securing remote administration directly reflects this component because it addresses the security considerations that must be managed when changes are made to how software is accessed and controlled remotely. This includes implementing secure protocols, authentication methods, and monitoring to prevent unauthorized access or breaches, which are crucial when managing changes in a secure manner.


Change management in cybersecurity emphasizes the structured approach to implementing alterations in security protocols, technologies, and processes, ensuring systematic assessment and monitoring1.

The role of change management in cybersecurity includes decisions about network access and ensuring the right person can access the right information at the right time, which aligns with securing remote administration2.

Seminal change management models in cybersecurity, like PROSCI's ADKAR model, guide individuals through the change process, managing resistance and identifying training needs, which is relevant to securing remote administration3.

Question 10

Which design and development deliverable contains the types of evaluations that were performed, how many times they were performed, and how many times they were re-evaluated?

Correct Answer: C. Security testing reports
Explanation:

Security testing reports are the most likely deliverables to contain detailed records of evaluations, their frequency, and re-evaluations. Here's why:

Purpose of Security Testing Reports: These reports document the results of security testing, including:

Types of tests: Vulnerability scans, penetration tests, code reviews, etc.

Frequency: How often tests were conducted (e.g., per build, per release cycle).

Re-evaluations: If vulnerabilities were discovered, these reports will track whether and how often those were retested after remediation.

Focus on Testing: The question specifically emphasizes evaluations, which aligns with the core content of security testing reports.