WGU certification preparation

SECURE-SOFTWARE-DESIGN Practice Questions

Practice exam-style questions, check your answers, and review explanations and source references where they are available.

Exam
SECURE-SOFTWARE-DESIGN
Provider
WGU
Full set
118 questions
Last Update Check
The product team has been tasked with updating the user interface (UI). They will change the layout and also add restrictions to field lengths and what data will be accepted. Which secure coding practice is this?
Answer options
Automated security testing was performed by attempting to log in to the new product with a known username using a collection of passwords. Access was granted after a few hundred attempts. How should existing security controls be adjusted to prevent this in the future?
Answer options
What is a best practice of secure coding?
Answer options
Using a web-based common vulnerability scoring system (CVSS) calculator, a security response team member performed an assessment on a reported vulnerability in the company's customer portal. The base score of the vulnerability was 9.9 and changed to 8.0 after adjusting temporal and environmental metrics. Which rating would CVSS assign this vulnerability?
Answer options
Which category classifies identified threats that do not have defenses in place and expose the application to exploits?
Answer options
Company leadership has discovered an untapped revenue stream within its customer base and wants to meet with IT to share its vision for the future and determine whether to move forward. Which phase of the software development lifecycle (SDLC) is being described?
Answer options
Which threat modeling step identifies the assets that need to be protected?
Answer options
The security software team has cloned the source code repository of the new software product so they can perform vulnerability testing by modifying or adding small snippets of code to see if they can cause unexpected behavior and application failure. Which security testing technique is being used?
Answer options
The product security incident response team (PSIRT) has decided to make a formal public disclosure, including base and temporal common vulnerability scoring system (CVSS) scores and a common vulnerabilities and exposures (CVE) ID report, of an externally discovered vulnerability. What is the most likely reason for making a public disclosure?
Answer options
Which architecture deliverable identifies the organization's tolerance to security issues and how the organization plans to react if a security issue occurs?
Answer options
Question 1 of 10

Source context

How this practice set is maintained

Maintained by the CertMage content team, this page loads questions from the exam dataset connected to its preparation resource. When an answer includes a supporting reference, it is shown with that answer so you can review the underlying vendor documentation.

Certification objectives, interfaces, and vendor services can change. Verify important details against the provider's current exam guide and documentation before your exam.

Scroll to Top