Exam (elaborations)
WGU MASTER'S COURSE C706 - SECURE SOFTWARE DESIGN
Course
WGU MASTER\\\'S COURSE C706 - SECURE SOFTWARE DESIGN
Institution
WGU MASTER\\\'S COURSE C706 - SECURE SOFTWARE DESIGN
WGU MASTER'S COURSE C706 - SECURE SOFTWARE DESIGN
[Show more]
Preview 4 out of 44 pages
Uploaded on
November 12, 2024
Number of pages
44
Written in
2024/2025
Type
Exam (elaborations)
Contains
Questions & answers
Institution
WGU MASTER'S COURSE C706 - SECURE SOFTWARE DESIGN
Course
WGU MASTER'S COURSE C706 - SECURE SOFTWARE DESIGN
$13.49
Also available in package deal from $17.99
100% satisfaction guarantee
Immediately available after payment
Both online and in PDF
No strings attached
Also available in package deal (1)
1. Exam (elaborations) - Wgu master's course c706 test bank - secure software design exam latest 2024 actual e...
2. Exam (elaborations) - Wgu master's course c706 - secure software design
Show more
WGU MASTER'S COURSE C706 -
SECURE SOFTWARE DESIGN
Whichgduegdiligencegactivitygforgsupplygchaingsecuritygshouldgoccurgingtheginitiationgphase
gofgthegsoftwaregacquisitionglifegcycle?
AgDevelopinggagrequestgforgproposalg(RFP)gthatgincludesgsupplygchaingsecuritygriskgmana
gement
BgLesseninggthegriskgofgdisseminatingginformationgduringgdisposal
CgFacilitatinggknowledgegtransfergbetweengsuppliers
DgMitigatinggsupplygchaingsecuritygriskgbygprovidinggusergguidanceg-gans--A
Whichgduegdiligencegactivitygforgsupplygchaingsecurityginvestigatesgthegmeansgbygwhichgd
atagsetsgaregsharedgandgassessed?
Agon-sitegassessment
Bgprocessgpolicygreview
Cgthird-partygassessment
Dgdocumentgexchangegandgreviewg-gans--D
Considergthesegcharacteristics:
-Identificationgofgthegentitygmakinggthegaccessgrequest
-Verificationgthatgthegrequestghasgnotgchangedgsincegitsginitiation
-Applicationgofgthegappropriategauthorizationgprocedures
-Reexaminationgofgpreviouslygauthorizedgrequestsgbygthegsamegentity
Whichgsecuritygdesignganalysisgisgbeinggdescribed?
AgOpengdesign
BgCompletegmediation
CgEconomygofgmechanism
DgLeastgcommongmechanismg-gans--B
Whichgsoftwaregsecuritygprinciplegguardsgagainstgthegimpropergmodificationgorgdestructio
ngofginformationgandgensuresgthegnonrepudiationgandgauthenticitygofginformation?
AgQuality
BgIntegrity
CgAvailability
DgConfidentialityg-gans--B
,Whatgtypegofgfunctionalgsecuritygrequirementginvolvesgreceiving,gprocessing,gstoring,gtran
smitting,gandgdeliveringgingreportgform?
AgLogging
BgErrorghandling
CgPrimarygdataflow
DgAccessgcontrolgflowg-gans--C
Whichgnonfunctionalgsecuritygrequirementgprovidesgagwaygtogcaptureginformationgcorrectl
ygandgagwaygtogstoregthatginformationgtoghelpgsupportglatergaudits?
AgLogging
BgErrorghandling
CgPrimarygdataflow
DgAccessgcontrolgflowg-gans--A
Whichgsecuritygconceptgrefersgtogthegqualitygofginformationgthatgcouldgcausegharmgorgdam
agegifgdisclosed?
AgIsolation
BgDiscretion
CgSeclusion
DgSensitivityg-gans--D
Whichgtechnologygwouldgbegangexamplegofganginjectiongflaw,gaccordinggtogthegOWASPgT
opg10?
AgSQL
BgAPI
CgXML
DgXSSg-gans--A
Agcompanygisgcreatinggagnewgsoftwaregtogtrackgcustomergbalancegandgwantsgtogdesigngag
securegapplication.
Whichgbestgpracticegshouldgbegapplied?
AgDevelopgagsecuregauthenticationgmethodgthatghasgagclosedgdesign
BgAllowgmediationgbypassgorgsuspensiongforgsoftwaregtestinggandgemergencygplanning
CgEnsuregtheregisgphysicalgacceptabilitygtogensuregsoftwaregisgintuitivegforgthegusersgtogdo
gtheirgjobs
DgCreategmultipleglayersgofgprotectiongsogthatgagsubsequentglayergprovidesgprotectiongifga
glayergisgbreachedg-gans--D
,Agcompanygisgdevelopinggagsecuregsoftwaregthatghasgtogbegevaluatedgandgtestedgbygaglar
gegnumbergofgexperts.
Whichgsecuritygprinciplegshouldgbegapplied?
AgFailgsafe
BgOpengdesign
CgDefensegingdepth
DgCompletegmediationg-gans--B
WhichgtypegofgTCPgscanninggindicatesgthatgagsystemgisgmovinggtogthegsecondgphaseginga
gthree-waygTCPghandshake?
AgTCPgSYNgscanning
BgTCPgACKgscanning
CgTCPgXMASgscanning
DgTCPgConnectgscanningg-gans--A
Whichgevaluationgtechniquegprovidesginvalid,gunexpected,gorgrandomgdatagtogtheginputsg
ofgagcomputergsoftwaregprogram?
AgFuzzgtesting
BgStaticganalysis
CgDynamicganalysis
DgRegressiongtestingg-gans--A
Whichgapproachgprovidesgangopportunitygtogimprovegthegsoftwaregdevelopmentglifegcycleg
bygtailoringgthegprocessgtogthegspecificgrisksgfacinggthegorganization?
AgAgilegmethodology
BgWaterfallgmethodology
CgBuildinggsecuritygingmaturitygmodelg(BSIMM)
DgSoftwaregassurancegmaturitygmodelg(SAMM)g-gans--D
Whichgphasegcontainsgsophisticatedgsoftwaregdevelopmentgprocessesgthatgensuregthatgf
eedbackgfromgonegphasegreachesgtogthegpreviousgphasegtogimprovegfuturegresults?
AgInitial
BgManaged
CgOptimizing
DgRepeatableg-gans--C
Thegactivitiesgforgcompliancegincludegensuringgcollectedginformationgisgonlygusedgforginte
ndedgpurposes,ginformationgisgtimelygandgaccurate,gandgthegpublicgisgawaregofgtheginform
ationgcollectedgandghowgitgisgused.
, Whichgwell-acceptedgsecuregdevelopmentgstandardgisgaddressedgbygthesegactivities?
AgPIA
BgPA-DSS
CgPCI-DSS
DgPTS-DSSg-gans--A
Angorganizationgisgingthegprocessgofgbuildinggangapplicationgforgitsgbankinggsoftware.
Whichgsecuritygcodinggpracticegmustgthegorganizationgfollow?
AgRungagdataganalysis
BgConductgdatagvalidation
CgValidategthegdatagsource
DgAligngbusinessggoalsg-gans--B
Whatgisgincludedgingagtypicalgjobgdescriptiongofgagsoftwaregsecuritygchampiong(SSC)?
AgIdentifygsoftwaregupdategsourcegandgsink
BgReviewgcodegtogidentifygskill-relatedgbugs
CgDevelopgandgmanagegthegafter-SDLCgstage
DgConsidergallgpossiblegpathsgofgattackgorgexploitsg-gans--D
Whichgrolegisgagtraininggchampiongofgsoftwaregsecurity,gangadvocategforgthegoverallgSDLg
process,gandgagproponentgforgpromulgatinggandgenforcinggthegoverallgsoftwaregproductgs
ecuritygprogram?
AgSoftwaregsecurityguserg(SSU)
BgSoftwaregsecuritygarchitectg(SSA)
CgSoftwaregsecuritygevangelistg(SSE)
DgSoftwaregsecuritygstakeholderg(SSS)g-gans--C
Whichgrolegrequiresgthegtechnicalgcapabilitygtogbegtrainedgasgagsoftwaregsecuritygarchitect
gwhogthengassistsgthegcentralizedgsoftwaregsecurityggroupgwithgarchitecturegsecurityganal
ysisgandgthreatgmodeling?
AgSoftwaregchampion
BgSoftwaregevangelist
CgJuniorgsoftwaregdeveloper
DgSeniorgsoftwaregprogrammerg-gans--A
Angapplicationgdevelopmentgteamgisgdesigninggandgbuildinggangapplicationgthatginterface
sgwithgagback-endgdatabase.
Whichgactivitygshouldgbegincludedgwhengconstructinggagthreatgmodelgforgthegapplication?