Summer Special 60% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: bestdeal

Free WGU Secure-Software-Design Practice Exam with Questions & Answers

Questions 1

Company leadership has discovered an untapped revenue stream within its customer base and wants to meet with IT to share its vision for the future and determine whether to move forward.

Which phase of the software development lifecycle (SDLC) is being described?

Options:
A.

Implementation

B.

Design

C.

Planning

D.

Requirements

WGU Secure-Software-Design Premium Access
Questions 2

What sits between a browser and an internet connection and alters requests and responses in a way the developer did not intend?

Options:
A.

Load testing

B.

Input validation

C.

Intercept proxy

D.

Reverse engineering

Questions 3

The software security team prepared a detailed schedule napping security development lifecycle phases to the type of analysis they will execute.

Which design and development deliverable aid the team prepare?

Options:
A.

Design security review

B.

Updated threat modeling artifacts

C.

Privacy implementation assessment results

D.

Security test plans

Questions 4

What is a best practice of secure coding?

Options:
A.

Planning

B.

Session management

C.

User acceptance testing

D.

Microservices

Questions 5

Which secure coding best practice says to use well-vetted algorithms to ensure that the application uses random identifiers, that identifiers are appropriately restricted to the application, and that user processes are fully terminated on logout?

Options:
A.

Output Encoding

B.

Input Validation

C.

Access Control

D.

Session Management

Questions 6

An individual is developing a software application that has a back-end database and is concerned that a malicious user may run the following SOL query to pull information about all accounts from the database:

Secure-Software-Design Question 6

Which technique should be used to detect this vulnerability without running the source codes?

Options:
A.

Dynamic analysis

B.

Cross-site scripting

C.

Static analysis

D.

Fuzz testing

Questions 7

During fuzz testing of the new product, random values were entered into input elements Search requests were sent to the correct API endpoint but many of them failed on execution due to type mismatches.

How should existing security controls be adjusted to prevent this in the future?

Options:
A.

Ensure all user input data is validated prior to transmitting requests

B.

Ensure all requests and responses are encrypted

C.

Ensure sensitive transactions can be traced through an audit log

D.

Ensure the contents of authentication cookies are encrypted

Questions 8

What is a countermeasure to the web application security frame (ASF) data validation/parameter validation threat category?

Options:
A.

Inputs enforce type, format, length, and range checks.

B.

All administrative activities are logged and audited.

C.

Sensitive information is not logged.

D.

All exceptions are handled in a structured way.

Questions 9

In which step of the PASTA threat modeling methodology will the team capture infrastructure, application, and software dependencies?

Options:
A.

Attack modeling

B.

Define technical scope

C.

Define objectives

D.

Risk and impact analysis

Questions 10

The organization has contracted with an outside firm to simulate an attack on the new software product and report findings and remediation recommendations.

Which activity of the Ship SDL phase is being performed?

Options:
A.

Penetration testing

B.

Policy compliance analysis

C.

Open-source licensing review

D.

Final security review

Certification Provider: WGU
Exam Name: WGU Secure Software Design (D487, KEO1) Exam
Last Update: Sep 12, 2025
Questions: 118

WGU Related Exams

How to pass WGU Scripting-and-Programming-Foundations - WGU Scripting and Programming Foundations Exam Exam
How to pass WGU Managing-Human-Capital - WGU Managing Human Capital C202 Exam
How to pass WGU Integrated-Physical-Sciences - WGU Integrated Physical Sciences (MTC1) Exam
How to pass WGU Cybersecurity-Architecture-and-Engineering - WGU Cybersecurity Architecture and Engineering (KFO1/D488) Exam
How to pass WGU Organizational-Behaviors-and-Leadership - WGU Organizational Behaviors and Leadership (IBC1) Exam
How to pass WGU Principles-of-Management - Principles of Management at Western Governors University(IAC1) Exam
How to pass WGU Web-Development-Applications - WGU Web Development Applications (KVO1) Exam
How to pass WGU Ethics-In-Technology - WGU Ethics In Technology QCO1 Exam
How to pass WGU Information-Technology-Management - WGU Information Technology Management QGC1 Exam
How to pass WGU Network-and-Security-Foundation - Network-and-Security-Foundation Exam
How to pass WGU Data-Management-Foundations - WGU Data Management – Foundations Exam Exam
How to pass WGU Cloud-Deployment-and-Operations - WGUCloud Deployment and Operations Exam

WGU Free Exams

WGU Free Exams
Examstrack offers comprehensive free resources and practice tests for WGU exams.