Pass the WGU Courses and Certificates Secure-Software-Design Questions and answers with CertsForce

Viewing page 3 out of 4 pages
Viewing questions 21-30 out of questions
Questions # 21:

Which software control test examines an application from a user perspective by providing a wide variety of input scenarios and inspecting the output?

Options:

A.

Dynamic


B.

Black box


C.

Static


D.

White box


Expert Solution
Questions # 22:

Which secure coding best practice ensures sensitive information is not disclosed in any responses to users, authorized or unauthorized?

Options:

A.

Input validation


B.

System configuration


C.

Authentication and password management


D.

Error handling and logging


Expert Solution
Questions # 23:

Automated security testing was performed by attempting to log in to the new product with a known username using a collection of passwords. Access was granted after a few hundred attempts.

How should existing security controls be adjusted to prevent this in the future?

Options:

A.

Ensure passwords are encrypted when stored in persistent data stores


B.

Ensure authentication controls are resistant to brute force attacks


C.

Ensure strong password policies are enforced


D.

Ensure credentials and authentication tokens are encrypted during transit


Expert Solution
Questions # 24:

During fuzz testing of the new product, random values were entered into input elements Search requests were sent to the correct API endpoint but many of them failed on execution due to type mismatches.

How should existing security controls be adjusted to prevent this in the future?

Options:

A.

Ensure all user input data is validated prior to transmitting requests


B.

Ensure all requests and responses are encrypted


C.

Ensure sensitive transactions can be traced through an audit log


D.

Ensure the contents of authentication cookies are encrypted


Expert Solution
Questions # 25:

Which mitigation technique can be used to light against a threat where a user may gain access to administrator level functionality?

Options:

A.

Encryption


B.

Quality of service


C.

Hashes


D.

Run with least privilege


Expert Solution
Questions # 26:

What is one of the tour core values of the agile manifesto?

Options:

A.

Communication between team members


B.

Individuals and interactions over processes and tools


C.

Business people and developers must work together daily throughout the project.


D.

Teams should have a dedicated and open workspace.


Expert Solution
Questions # 27:

The security team is reviewing all noncommercial software libraries used in the new product to ensure they are being used according to the legal specifications defined by the authors.

What activity of the Ship SDL phase is being performed?

Options:

A.

Policy compliance analysis


B.

Open-source licensing review


C.

Penetration testing


D.

Final security review


Expert Solution
Questions # 28:

The security testing team received a report from one of the contracted penetration testing vendors that details a flaw discovered in the login component of the new software product, along with a recommended fix.

Which phase of the penetration testing process is the team in?

Options:

A.

Identify


B.

Evaluate and plan


C.

Deploy


D.

Assess


Expert Solution
Questions # 29:

The software security group is conducting a maturity assessment using the Open Web Application Security Project Software Assurance Maturity Model (OWASP SAMM). They are currently focused on reviewing design artifacts to ensure they comply with organizational security standards.

Which OpenSAMM business function is being assessed?

Options:

A.

Verification


B.

Construction


C.

Deployment


D.

Governance


Expert Solution
Questions # 30:

Which secure coding best practice says to only use tested and approved components and use task-specific, built-in APIs to conduct operating system functions?

Options:

A.

Session Management


B.

Authentication and Password Management


C.

Data Protection


D.

General Coding Practices


Expert Solution
Viewing page 3 out of 4 pages
Viewing questions 21-30 out of questions