Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

WGU (D487, KEO1) Secure Software Design Exam - Topic 2 Question 7 Discussion

The software security group is conducting a maturity assessment using the Building Security in Maturity Model (BSIMM). They are currently focused on reviewing attack models created during recently completed initiatives.Which BSIMM domain is being assessed?
C) Intelligence
A) Governance
B) Software security development life cycle (SSDL) touchpoints
D) Deployment

WGU (D487, KEO1) Secure Software Design Exam - Topic 2 Question 7 Discussion

Actual exam question for WGU's WGU (D487, KEO1) Secure Software Design exam
Question #: 7
Topic #: 2
[All WGU (D487, KEO1) Secure Software Design Questions]

The software security group is conducting a maturity assessment using the Building Security in Maturity Model (BSIMM). They are currently focused on reviewing attack models created during recently completed initiatives.

Which BSIMM domain is being assessed?

Show Suggested Answer Hide Answer
Suggested Answer: C

The Intelligence domain in the Building Security in Maturity Model (BSIMM) focuses on gathering and using information about software security. This includes understanding the types of attacks that are possible against the software being developed, which is why reviewing attack models falls under this domain. The BSIMM domain of Intelligence involves creating models of potential attacks on software (attack models), analyzing actual attacks that have occurred (attack intelligence), and sharing this information to improve security measures. By reviewing attack models, the software security group is essentially assessing the organization's ability to anticipate and understand potential security threats, which is a key aspect of the Intelligence domain.


Contribute your Thoughts:

0/2000 characters
Amber
13 hours ago
I agree with Maybelle, it's all about understanding threats.
upvoted 0 times
...
Evan
6 days ago
I thought it was B) SSDL touchpoints. Makes more sense to me.
upvoted 0 times
...
Maybelle
11 days ago
Definitely C) Intelligence. That's where attack models fit.
upvoted 0 times
...
Jolanda
16 days ago
Really? I didn't expect it to be C) Intelligence!
upvoted 0 times
...
Walker
2 months ago
Wait, are we sure it's not D) Deployment?
upvoted 0 times
...
Bernardo
2 months ago
Seems like A) Governance could fit too.
upvoted 0 times
...
Nelida
2 months ago
I thought it was B) SSDL touchpoints!
upvoted 0 times
...
Latonia
3 months ago
Definitely C) Intelligence, right?
upvoted 0 times
...
Kattie
3 months ago
I feel like this is definitely about the Intelligence domain, but I might be mixing it up with something else we studied.
upvoted 0 times
...
Verona
3 months ago
Governance seems like a possibility too, but I can't recall if it specifically covers attack models.
upvoted 0 times
...
Marsha
3 months ago
I remember practicing a question about SSDL touchpoints, but this one feels different since it's more about reviewing models.
upvoted 0 times
...
Daniela
3 months ago
I think the focus on attack models might relate to the Intelligence domain, but I'm not entirely sure.
upvoted 0 times
...
Eun
3 months ago
I’m leaning towards the Intelligence domain too, but I could see how it might connect to Deployment if they’re assessing how those models are applied.
upvoted 0 times
...
Noelia
4 months ago
I feel like I’ve seen a question similar to this before, and it was about Governance. But attack models seem more tactical, so maybe it’s not that.
upvoted 0 times
...
Celeste
4 months ago
I remember something about SSDL touchpoints being related to the development process, but this seems more focused on the analysis of threats.
upvoted 0 times
...
Muriel
4 months ago
I think this might relate to the Intelligence domain since they’re reviewing attack models, but I’m not entirely sure.
upvoted 0 times
...

Save Cancel