Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilDevSecOps Essentials

Domain 1Objective 4

Common Application Security Risks and OWASP Top 10 DSE Practice Questions (Page 2)

Part of the Application Development and Security Fundamentals domain, which makes up ~20% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 2–3 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)

37questions here
8free pages
4concepts

Questions 6–10

  1. 6application · medium

    A company is developing a new web application and wants to ensure that it is secure from the start. The team is considering using the OWASP Top 10 as a guide. Which approach best applies the OWASP Top 10 during the development lifecycle?

    Select an answer first
  2. 7expert · hard

    A security engineer is reviewing a web application that allows users to upload and share documents. The application uses a third-party file storage service. The engineer discovers that the application does not validate the file content, only the file extension. An attacker uploads a file with a .txt extension but containing malicious HTML. When other users download and open the file, the script executes in their browser. Which OWASP Top 10 risk is most directly demonstrated, and what is the best mitigation?

    Select an answer first
  3. 8expert · hard

    A company is migrating a legacy web application to the cloud. The application currently stores user passwords using MD5 hashes. The security team wants to remediate this before the migration. The team has limited budget and must minimize downtime. Which approach best balances security and operational constraints?

    Select an answer first
  4. 9foundation · easy

    During a code review, a developer notices that a web application constructs SQL queries by directly concatenating user input into the query string. Which common application security risk does this practice most directly introduce?

    Select an answer first
  5. 10application · medium

    A developer is building a customer feedback form that stores comments in a SQL database. The form accepts free-text input and the developer concatenates the input directly into a SQL query. During a security review, a colleague points out that this pattern is listed in the OWASP Top 10. Which OWASP Top 10 category does this vulnerability belong to, and what is the most effective mitigation?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DSE” is a trademark of its owner, used for identification only.