WGU University KEO1 - Secure Software Design Exam

Question #11 (Topic: Exam A)
Which type of manual code review technique is being used when the reviewer starts at an input control and traces its value through the application to each of the value’s outputs?
A. Risk analysis B. Control flow analysis C. Data flow analysis D. Threat analysis
Answer: C
Question #12 (Topic: Exam A)
Which step in the change management process includes modifying the source code?
A. Patch management B. Installation management C. Privacy implementation assessment D. Policy compliance analysis
Answer: A
Question #13 (Topic: Exam A)
The security team is reviewing all noncommercial software libraries used in the new product to ensure they are being used according to the legal specifications defined by the authors.
What activity of the Ship SDL phase is being performed?
A. Policy compliance analysis B. Open-source licensing review C. Penetration testing D. Final security review
Answer: B
Question #14 (Topic: Exam A)
The organization is moving from a waterfall to an agile software development methodology, so the software security group must adapt the security development life cycle as well. They have decided to break out security requirements and deliverables to fit better in the iterative life cycle by defining every-sprint requirements, one-time requirements, bucket requirements, and final security review requirements.
Which type of requirement states that the team must identify primary security and privacy contacts?
A. Final security review requirement B. Bucket requirement C. Every-sprint requirement D. One-time requirement
Answer: D
Question #15 (Topic: Exam A)
Which category classifies identified threats that do not have defenses in place and expose the application to exploits?
A. Fully mitigated threat B. Threat profile C. Unmitigated threats D. Partially mitigated threat
Answer: C
Download Exam
Page: 3 / 14
Total 66 questions