WGU certification preparation
SECURE-SOFTWARE-DESIGN Practice Questions
Practice exam-style questions, check your answers, and review explanations and source references where they are available.
- Exam
- SECURE-SOFTWARE-DESIGN
- Provider
- WGU
- Full set
- 118 questions
- Last Update Check
The product team has been tasked with updating the user interface (UI). They will change the layout
and also add restrictions to field lengths and what data will be accepted.
Which secure coding practice is this?
Question 1 discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Automated security testing was performed by attempting to log in to the new product with a known
username using a collection of passwords. Access was granted after a few hundred attempts.
How should existing security controls be adjusted to prevent this in the future?
Question 2 discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
What is a best practice of secure coding?
Question 3 discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Using a web-based common vulnerability scoring system (CVSS) calculator, a security response team
member performed an assessment on a reported vulnerability in the company's customer portal.
The base score of the vulnerability was 9.9 and changed to 8.0 after adjusting temporal and
environmental metrics.
Which rating would CVSS assign this vulnerability?
Question 4 discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Which category classifies identified threats that do not have defenses in place and expose the
application to exploits?
Question 5 discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Company leadership has discovered an untapped revenue stream within its customer base and wants
to meet with IT to share its vision for the future and determine whether to move forward.
Which phase of the software development lifecycle (SDLC) is being described?
Question 6 discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Which threat modeling step identifies the assets that need to be protected?
Question 7 discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
The security software team has cloned the source code repository of the new software product so
they can perform vulnerability testing by modifying or adding small snippets of code to see if they
can cause unexpected behavior and application failure.
Which security testing technique is being used?
Question 8 discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
The product security incident response team (PSIRT) has decided to make a formal public disclosure,
including base and temporal common vulnerability scoring system (CVSS) scores and a common
vulnerabilities and exposures (CVE) ID report, of an externally discovered vulnerability.
What is the most likely reason for making a public disclosure?
Question 9 discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Which architecture deliverable identifies the organization's tolerance to security issues and how the
organization plans to react if a security issue occurs?
Question 10 discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Question 1 of 10
Source context
How this practice set is maintained
Maintained by the CertMage content team, this page loads questions from the exam dataset connected to its preparation resource. When an answer includes a supporting reference, it is shown with that answer so you can review the underlying vendor documentation.
Certification objectives, interfaces, and vendor services can change. Verify important details against the provider's current exam guide and documentation before your exam.
