Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilDevSecOps Essentials

Domain 1Objective 4

Common Application Security Risks and OWASP Top 10 DSE Practice Questions (Page 1)

Part of the Application Development and Security Fundamentals domain, which makes up ~20% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 2–3 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)

37questions here
8free pages
4concepts

Questions 1–5

  1. 1application · medium

    A security analyst is reviewing a web application that uses a captcha to prevent automated submissions. The captcha is implemented client-side and the server does not validate the captcha response. An attacker bypasses the captcha and floods the server with requests. Which OWASP Top 10 category is most relevant, and what is the best mitigation?

    Select an answer first
  2. 2application · medium

    A company is developing a REST API that returns JSON responses. The API uses API keys for authentication. The security team discovers that the API keys are hardcoded in the client-side JavaScript code. Which OWASP Top 10 risk is most directly demonstrated, and what is the best mitigation?

    Select an answer first
  3. 3application · medium

    A developer is reviewing code for an e-commerce application. The code builds a SQL query by concatenating a user-supplied product ID directly into the WHERE clause. The application is deployed behind a Web Application Firewall (WAF) that blocks common SQL injection patterns. The developer wants to fix the root cause. What is the most appropriate action?

    Select an answer first
  4. 4application · medium

    A web application allows users to view their own profile and edit it. A tester discovers that by changing the 'user_id' parameter in the URL, they can view and edit other users' profiles. Which OWASP Top 10 category does this vulnerability belong to, and what is the primary mitigation?

    Select an answer first
  5. 5application · medium

    A development team is building a customer portal that allows users to upload profile pictures. The portal stores the images in Azure Blob Storage and serves them directly to other users via public URLs. During a security review, the team discovers that an attacker could upload a file containing malicious script that executes when another user views the image. Which OWASP Top 10 category does this vulnerability primarily fall under, and what is the most effective mitigation?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DSE” is a trademark of its owner, used for identification only.