Weekend Sale 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: sale65best

Free WGU Secure-Software-Design Practice Exam with Questions & Answers | Set: 2

Questions 11

Which secure coding best practice says to require authentication before allowing any files to be uploaded and to limit the types of files to only those needed for the business purpose?

Options:
A.

File management

B.

Communication security

C.

Data protection

D.

Memory management

WGU Secure-Software-Design Premium Access
Questions 12

Which security assessment deliverable defines measures that can be periodically reported to management?

Options:
A.

Metrics Template

B.

SDL Project Outline

C.

Threat Profile

D.

Product Risk Profile

Questions 13

What refers to the review of software source code by developers other than the original coders to try to identify oversights, mistakes, assumptions, a lack of knowledge, or even experience?

Options:
A.

User acceptance testing

B.

Manual peer review

C.

Fault injection

D.

Dynamic code review

Questions 14

Which secure coding best practice says to use well-vetted algorithms to ensure that the application uses random identifiers, that identifiers are appropriately restricted to the application, and that user processes are fully terminated on logout?

Options:
A.

Output Encoding

B.

Input Validation

C.

Access Control

D.

Session Management

Questions 15

Which security assessment deliverable identities possible security vulnerabilities in the product?

Options:
A.

SDL project outline

B.

Metrics template

C.

Threat profile

D.

List of third-party software

Questions 16

Which software control test examines an application from a user perspective by providing a wide variety of input scenarios and inspecting the output?

Options:
A.

Dynamic

B.

Black box

C.

Static

D.

White box

Questions 17

Which type of threat exists when an attacker can intercept and manipulate form data after the user clicks the save button but before the request is posted to the API?

Options:
A.

Elevation of privilege

B.

Spoofing

C.

Tampering

D.

Information disclosure

Questions 18

A potential threat was discovered during automated system testing when a PATCH request sent to the API caused an unhandled server exception. The API only supports GET. POST. PUT, and DELETE requests.

How should existing security controls be adjusted to prevent this in the future?

Options:
A.

Property configure acceptable API requests

B.

Enforce role-based authorization

C.

Use API keys to enforce authorization of every request

D.

Ensure audit logs are in place for sensitive transactions

Questions 19

What sits between a browser and an internet connection and alters requests and responses in a way the developer did not intend?

Options:
A.

Load testing

B.

Input validation

C.

Intercept proxy

D.

Reverse engineering

Questions 20

Which design and development deliverable contains the types of evaluations that were performed, how many times they were performed, and how many times they were re-evaluated?

Options:
A.

Privacy compliance report

B.

Remediation report

C.

Security testing reports

D.

Security test execution report

Certification Provider: WGU
Exam Name: WGU Secure Software Design (D487) Exam
Last Update: Jul 20, 2025
Questions: 113

WGU Related Exams

How to pass WGU Managing-Human-Capital - WGU Managing Human Capital C202 Exam
How to pass WGU Integrated-Physical-Sciences - WGU Integrated Physical Sciences (MTC1) Exam
How to pass WGU Cybersecurity-Architecture-and-Engineering - WGU Cybersecurity Architecture and Engineering (D488) Exam
How to pass WGU Organizational-Behaviors-and-Leadership - WGU Organizational Behaviors and Leadership (IBC1) Exam
How to pass WGU Principles-of-Management - Principles of Management at Western Governors University(IAC1) Exam
How to pass WGU Web-Development-Applications - WGU Web Development Applications (KVO1) Exam
How to pass WGU Ethics-In-Technology - WGU Ethics In TechnologyQCO1 Exam
How to pass WGU Information-Technology-Management - WGU Information Technology Management QGC1 Exam
How to pass WGU Network-and-Security-Foundation - Network-and-Security-Foundation Exam
How to pass WGU Data-Management-Foundations - WGU Data Management – Foundations Exam Exam
How to pass WGU Cloud-Deployment-and-Operations - WGUCloud Deployment and Operations Exam

WGU Free Exams

WGU Free Exams
Examstrack offers comprehensive free resources and practice tests for WGU exams.