WGU-KEO1 Exam Details

  • Exam Code
    :WGU-KEO1
  • Exam Name
    :WGU Secure Software Design (D487, KEO1)
  • Certification
    :WGU University Certifications
  • Vendor
    :WGU University
  • Total Questions
    :133 Q&As
  • Last Updated
    :May 29, 2026

WGU University WGU-KEO1 Online Questions & Answers

  • Question 51:

    An attacker attempts to overwhelm an API by sending thousands of requests per second from a single client. Which mitigation technique is MOST effective against this threat?

    A. Encryption
    B. Authentication
    C. Throttling
    D. Auditing

  • Question 52:

    Which design and development deliverable contains the results of each type of evaluation that was performed and the type and number of vulnerabilities discovered?

    A. Security test execution report
    B. Security testing reports
    C. Privacy compliance report
    D. Remediation report

  • Question 53:

    A potential threat was discovered during automated system testing when a PATCH request sent to the API caused an unhandled server exception. The API only supports GET. POST. PUT, and DELETE requests. How should existing security controls be adjusted to prevent this in the future?

    A. Property configure acceptable API requests
    B. Enforce role-based authorization
    C. Use API keys to enforce authorization of every request
    D. Ensure audit logs are in place for sensitive transactions

  • Question 54:

    While performing functional testing of the new product from a shared machine, a QA analyst closed their browser window but did not logout of the application. A different QA analyst accessed the application an hour later and was not prompted to login. They then noticed the previous analyst was still logged into the application. How should existing security controls be adjusted to prevent this in the future?

    A. Ensure no sensitive information is stored in plain text in cookies
    B. Ensure user sessions timeout after short intervals
    C. Ensure role-based access control is enforced for access to all resources
    D. Ensure strong password policies are enforced

  • Question 55:

    What are the three primary goals of the secure software development process?

    A. Performance, reliability, and maintainability
    B. Cost, speed to market, and profitability
    C. Redundancy, scalability, and portability
    D. Confidentiality, integrity, and availability

  • Question 56:

    Which privacy impact statement requirement type defines how personal information will be protected when authorized or independent external entities are involved?

    A. Personal information retention requirements
    B. User controls requirements
    C. Third party requirements
    D. Data integrity requirements

  • Question 57:

    What are the eight phases of the software development lifecycle (SDLC)?

    A. Planning, security analysis, requirement analysis, design, implementation, threat mitigation, testing, maintenance
    B. Planning, requirements, design, implementation, testing, deployment, maintenance, end of life
    C. Plan, gather requirements, identify attack surface, design, write code, perform code reviews, test, deploy
    D. Gather requirements, prototype, perform threat modeling, write code, test, user acceptance testing, deploy, maintain

  • Question 58:

    What is the last slop of the SDLOSDL code review process?

    A. Review for security issues unique to the architecture
    B. Identify security code review objectives
    C. Perform preliminary scan
    D. Review code for security issues

  • Question 59:

    A security team evaluates how user data moves from a web form through business logic and into a database during a manual review. Which manual code review technique is being applied?

    A. Control flow analysis
    B. Data flow analysis
    C. Threat analysis
    D. Risk assessment

  • Question 60:

    Which DREAD category is based on how easily a threat exploit can be found?

    A. Damage Potential
    B. Affected Users
    C. Discoverability
    D. Reproducibility

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only WGU University exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your WGU-KEO1 exam preparations and WGU University certification application, do not hesitate to visit our Vcedump.com to find your solutions here.