Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

WGU (D487, KEO1) Secure Software Design Exam - Topic 2 Question 10 Discussion

Actual exam question for WGU's WGU (D487, KEO1) Secure Software Design exam
Question #: 10
Topic #: 2
[All WGU (D487, KEO1) Secure Software Design Questions]

The software security team prepared a report of necessary coding and architecture changes identified during the security assessment.

Which design and development deliverable did the team prepare?

Show Suggested Answer Hide Answer
Suggested Answer: A

Comprehensive and Detailed In-Depth Explanation:

In the context of software security, a threat model is a structured representation that identifies potential threats to the system, evaluates their severity, and guides the development of mitigation strategies. When a security assessment reveals vulnerabilities or areas of concern, it's imperative to update the threat modeling artifacts to reflect these findings. This ensures that the threat model remains an accurate and current representation of the system's security posture.

By updating the threat modeling artifacts, the team documents the identified threats and outlines necessary coding and architectural changes to mitigate these threats. This proactive approach allows for the integration of security considerations early in the design and development phases, reducing the likelihood of vulnerabilities in the deployed system.

This practice aligns with the Design business function of the OWASP Software Assurance Maturity Model (SAMM), which emphasizes the importance of incorporating security into the software design process. Within this function, the Threat Assessment practice focuses on identifying and evaluating potential threats to inform security requirements and design decisions. Updating threat modeling artifacts is a key activity within this practice, ensuring that security assessments directly influence the system's design and architecture.


OWASP SAMM: Design - Threat Assessment

Contribute your Thoughts:

0/2000 characters
Stefany
17 days ago
I practiced a question similar to this, and I feel like security test plans are more about testing than actual design changes, so I’m leaning away from B.
upvoted 0 times
...
Lindsay
22 days ago
I'm not entirely sure, but I remember something about threat modeling being important for security assessments, so maybe A) Updated threat modeling artifacts?
upvoted 0 times
...
Blythe
27 days ago
I think the answer might be D) Design security review, since it relates to changes in design based on the assessment.
upvoted 0 times
...

Save Cancel