Limited-Time Offer: Enjoy 50% Savings! - Ends In 0d 00h 00m 00s Coupon code: 50OFF
Free Exam Questions

Secure-Software-Design Exam Questions & Answers

WGU Secure Software Design (D487, KEO1) Exam  •  WGU

118 Questions Updated Sep 2026 99% Pass Rate
Get Full Access

100% money-back guarantee

Sample Secure-Software-Design Questions

Practice with real exam-style questions, each with the verified correct answer and explanation.

Q1 MultipleChoice

What is the protection of information and information systems from unauthorized access, use, disclosure, disruption, modification, or distribution to provide confidentiality, integrity, and availability?

Correct Answer: D
Q2 MultipleChoice

Which security assessment deliverable identities possible security vulnerabilities in the product?

Correct Answer: C
Explanation:

A threat profile is a security assessment deliverable that identifies possible security vulnerabilities in a product. It involves a systematic examination of the product to uncover any weaknesses that could potentially be exploited by threats. The process typically includes identifying the assets that need protection, assessing the threats to those assets, and evaluating the vulnerabilities that could be exploited by those threats. This deliverable is crucial for understanding the security posture of a product and for prioritizing remediation efforts.

Q3 MultipleChoice

Credit card numbers are encrypted when stored in the database but are automatically decrypted when data is fetched. The testing tool intercepted the GET response, and testers were able to view credit card numbers as clear text.

How should the organization remediate this vulnerability?

Correct Answer: C
Explanation:

The core issue here is cleartext transmission of sensitive data, and option C directly addresses this:

Addressing the Problem: The scenario reveals the vulnerability is the lack of encryption during data transmission (the GET response). Ensuring encryption in transit fixes this specific exploit.

Transport Layer Security: Encryption during transit is typically achieved through protocols like TLS (HTTPS), preventing the interception of sensitive information.

Q4 MultipleChoice

Which secure coding best practice says to only use tested and approved components and use task-specific, built-in APIs to conduct operating system functions?

Correct Answer: D
Q5 MultipleChoice

Which design and development deliverable contains the types of evaluations that were performed, how many times they were performed, and how many times they were re-evaluated?

Correct Answer: C
Explanation:

Security testing reports are the most likely deliverables to contain detailed records of evaluations, their frequency, and re-evaluations. Here's why:

Purpose of Security Testing Reports: These reports document the results of security testing, including:

Types of tests: Vulnerability scans, penetration tests, code reviews, etc.

Frequency: How often tests were conducted (e.g., per build, per release cycle).

Re-evaluations: If vulnerabilities were discovered, these reports will track whether and how often those were retested after remediation.

Focus on Testing: The question specifically emphasizes evaluations, which aligns with the core content of security testing reports.

Get access to all 118 verified questions with detailed answers.

Unlock All Secure-Software-Design Questions

Frequently Asked Questions

The Secure Software Design (D487) exam, also known as KEO1, is a WGU certification assessment that evaluates your knowledge of secure coding practices, threat modeling, and secure software development lifecycle principles. This exam is ideal for software developers, security professionals, and IT students who want to demonstrate competency in building secure applications from the ground up.

The exam covers key areas including secure design principles, threat modeling, secure coding practices, authentication and authorization, cryptography basics, input validation, secure communication protocols, and vulnerability assessment. You'll also need to understand how to apply security throughout the software development lifecycle and identify common vulnerabilities like those listed in OWASP Top 10.

The D487 exam typically consists of multiple-choice and scenario-based questions that must be completed within a set timeframe. While specific passing scores may vary, WGU generally requires a score of 70% or higher to pass most certification exams, though you should verify the exact requirements with WGU.

WGU provides course materials, videos, and interactive content within their learning environment that directly align with the exam objectives. Additionally, studying OWASP resources, reviewing secure coding guidelines, practicing threat modeling exercises, and exploring real-world case studies of software vulnerabilities will strengthen your preparation.

Yes, WGU typically allows students to retake certification exams if they don't achieve a passing score on the first attempt. However, you may need to wait a certain period between attempts and should review your exam feedback to identify weak areas before retaking the test.
Exam Details
  • Exam CodeSecure-Software-Design
  • VendorWGU
  • Total Questions118
  • LanguageEnglish
  • Last UpdatedSep 5, 2026
4.9/5

Pass Secure-Software-Design First Time

Get all 118 exam questions with verified answers and 90-day free updates.

Buy Now & Pass
  • PDF + Practice Test Bundle
  • 90-Day Free Updates
  • 100% Money-Back Guarantee
  • Instant Download
  • 24/7 Customer Support
99% Pass Rate Trusted by 50,000+ IT professionals