Quality Secure-Software-Design PDF Dumps – Secure-Software-Design Exam Questions [Q28-Q48]

4.6/5 - (5 votes)

Quality Secure-Software-Design PDF Dumps – Secure-Software-Design Exam Questions

Most UptoDate WGU Secure-Software-Design Exam Dumps PDF 2025

Q28. The security team is reviewing all noncommercial software libraries used in the new product to ensure they are being used according to the legal specifications defined by the authors.
What activity of the Ship SDL phase is being performed?

 
 
 
 

Q29. What is a countermeasure to the web application security frame (ASF) authentication threat category?

 
 
 
 

Q30. The organization is moving from a waterfall to an agile software development methodology, so the software security group must adapt the security development life cycle as well. They have decided to break out security requirements and deliverables to fit better in the iterative life cycle by defining every-sprint requirements, one-time requirements, bucket requirements, and final security review requirements.
Which type of requirement slates that the team must identify primary security and privacy contacts?

 
 
 
 

Q31. The security team has a library of recorded presentations that are required viewing tor all new developers in the organization. The video series details organizational security policies and demonstrates how to define, test for. and code tor possible threats.
Which category of secure software best practices does this represent?

 
 
 
 

Q32. An individual is developing a software application that has a back-end database and is concerned that a malicious user may run the following SOL query to pull information about all accounts from the database:

Which technique should be used to detect this vulnerability without running the source codes?

 
 
 
 

Q33. While performing functional testing of the ordering feature in the new product, a tester noticed that the order object was transmitted to the POST endpoint of the API as a human-readable JSON object.
How should existing security controls be adjusted to prevent this in the future?

 
 
 
 

Q34. While performing functional testing of the new product from a shared machine, a QA analyst closed their browser window but did not logout of the application. A different QA analyst accessed the application an hour later and was not prompted to login. They then noticed the previous analyst was still logged into the application.
How should existing security controls be adjusted to prevent this in the future?

 
 
 
 

Q35. The software security team is performing security testing on a new software product using a testing tool that scans the running application for known exploit signatures.
Which security testing technique is being used?

 
 
 
 

Q36. Which type of threat exists when an attacker can intercept and manipulate form data after the user clicks the save button but before the request is posted to the API?

 
 
 
 

Q37. While performing functional testing of the new product from a shared machine, a QA analyst closed their browser window but did not logout of the application. A different QA analyst accessed the application an hour later and was not prompted to login. They then noticed the previous analyst was still logged into the application.
How should existing security controls be adjusted to prevent this in the future?

 
 
 
 

Q38. The software security team has been tasked with assessing a document management application that has been in use for many years and developing a plan to ensure it complies with organizational policies.
Which post-release deliverable is being described?

 
 
 
 

Q39. A potential threat was discovered during vulnerability testing when an environment configuration file was found that contained the database username and password stored in plain text.
How should existing security controls be adjusted to prevent this in the future?

 
 
 
 

Q40. Which secure coding best practice says to assume all incoming data should be considered untrusted and should be validated to ensure the system only accepts valid data?

 
 
 
 

Q41. Which threat modeling methodology involves creating or using collections of similar threats?

 
 
 
 

Q42. What is a countermeasure to the web application security frame (ASF) data validation/parameter validation threat category?

 
 
 
 

Q43. The final security review determined that two low-risk security issues identified in testing are still outstanding. Developers have assured the security team that both issues can be resolved quickly once they have time to fix them. The security team is confident that developers can fix the flaws in the first post-release patch.
What is the result of the final security review?

 
 
 
 

Q44. A new product does not display personally identifiable information, will not let private documents be printed, and requires elevation of privilege to retrieve archive documents. Which secure coding practice is this describing?

 
 
 
 

Q45. What is an advantage of using the Agile development methodology?

 
 
 
 

Q46. Which mitigation technique is used to fight against an identity spoofing threat?

 
 
 
 

Q47. Which secure coding best practice says to ensure that buffers are allocated correctly and at the right size, that input strings are truncated to a reasonable length, and that resources, connections, objects, and file handles are destroyed once the application no longer needs them?

 
 
 
 

Q48. What is the last slop of the SDLOSDL code review process?

 
 
 
 

100% Free Courses and Certificates Secure-Software-Design Dumps PDF Demo Cert Guide Cover: https://www.it-tests.com/Secure-Software-Design.html

         

Related Links: www.stes.tyc.edu.tw myportal.utt.edu.tt myportal.utt.edu.tt www.stes.tyc.edu.tw www.stes.tyc.edu.tw myportal.utt.edu.tt