WGU-KEO1 Exam Details

  • Exam Code
    :WGU-KEO1
  • Exam Name
    :WGU Secure Software Design (D487, KEO1)
  • Certification
    :WGU University Certifications
  • Vendor
    :WGU University
  • Total Questions
    :133 Q&As
  • Last Updated
    :May 29, 2026

WGU University WGU-KEO1 Online Questions & Answers

  • Question 61:

    The software security team is performing security testing for a new software product that is close to production release. They are concentrating on integrations between the new product and database servers, web servers, and web services. Which security testing technique is being used?

    A. Fuzz testing
    B. Dynamic code analysis
    C. Binary fault injection
    D. Binary code analysis

  • Question 62:

    Which secure coding best practice says to use well-vetted algorithms to ensure that the application uses random identifiers, that identifiers are appropriately restricted to the application, and that user processes are fully terminated on logout?

    A. Output Encoding
    B. Input Validation
    C. Access Control
    D. Session Management

  • Question 63:

    What is an advantage of using the Agile development methodology?

    A. Customer satisfaction is improved through rapid and continuous delivery of useful software.
    B. Each stage is clearly defined, making it easier to assign clear roles to teams and departments who feed into the project.
    C. The overall plan fits very neatly into a Gantt chart so a project manager can easily view the project timeline.
    D. There is much less predictability throughout the project regarding deliverables.

  • Question 64:

    The software security group is conducting a maturity assessment using the Open Web Application Security Project Software Assurance Maturity Model (OWASP OpenSAMM). They are currently focused on reviewing design artifacts to ensure they comply with organizational security standards. Which OpenSAMM business function is being assessed?

    A. Construction
    B. Deployment
    C. Verification
    D. Governance

  • Question 65:

    The software security team prepared a report of necessary coding and architecture changes identified during the security assessment. Which design and development deliverable did the team prepare?

    A. Updated threat modeling artifacts
    B. Security test plans
    C. Privacy implementation assessment results
    D. Design security review

  • Question 66:

    A development team is beginning work on a new internal web application that will process employee payroll data. Before any code is written, the security team is asked to identify potential attack vectors and sensitive assets. Which activity is MOST appropriate at this stage of the secure software development lifecycle (SDLC)?

    A. Dynamic security testing
    B. Threat modeling
    C. Penetration testing
    D. Incident response planning

  • Question 67:

    During penetration testing, an analyst was able to create hundreds of user accounts by executing a script that sent individual requests to the registration endpoint. How should the organization remediate this vulnerability?

    A. Use a Tool Like CAPTCHA to Prevent Batched Registrations and Bots
    B. Enforce Strong Password Complexity Standards
    C. Enforce Idle Time-Outs on Session IDs
    D. Ensure All Data Is Encrypted in Transit

  • Question 68:

    Which secure coding best practice says to only use tested and approved components and use task-specific, built-in APIs to conduct operating system functions?

    A. Session Management
    B. Authentication and Password Management
    C. Data Protection
    D. General Coding Practices

  • Question 69:

    Which security assessment deliverable defines measures that can be periodically reported to management?

    A. Metrics Template
    B. SDL Project Outline
    C. Threat Profile
    D. Product Risk Profile

  • Question 70:

    A new product does not display personally identifiable information, will not let private documents be printed, and requires elevation of privilege to retrieve archive documents. Which secure coding practice is this describing?

    A. Access control
    B. Data protection
    C. Input validation
    D. Authentication

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only WGU University exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your WGU-KEO1 exam preparations and WGU University certification application, do not hesitate to visit our Vcedump.com to find your solutions here.