
EC-CouncilCloud Security Essentials
Domain 5Objective 3
Secure Coding Practices CSE Practice Questions (Page 7)
Part of the Application Security in the Cloud domain, which makes up ~16% of our current practice bank.
60questions here
12free pages
12concepts
Questions 31–35
- 31
A company is adopting a secure development lifecycle (SDL) for their cloud applications. They want to integrate security practices into every phase of development. Which action best exemplifies this approach?
Select an answer first - 32
A development team uses several open-source libraries in their application. The security team discovers that one library has a known critical vulnerability. The library is used in a non-critical feature. What should the team do?
Select an answer first - 33
A development team uses several open-source libraries in their cloud application. The security team wants to ensure that known vulnerabilities in these dependencies are identified and addressed. Which practice should they implement?
Select an answer first - 34
A team is designing a new cloud-based application that will handle sensitive health data. The application will be accessed by patients and healthcare providers. The team must ensure that patients can only view their own records, while providers can view records for their assigned patients. Which threat modeling approach best addresses this requirement?
Select an answer first - 35
A development team uses a popular open-source library that has a critical vulnerability. The library is widely used in the application, and no patched version is available yet. The application is scheduled for release in two weeks. What is the best course of action?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSE” is a trademark of its owner, used for identification only.