
EC-CouncilDevSecOps Essentials
Domain 1Objective 4
Common Application Security Risks and OWASP Top 10 DSE Practice Questions (Page 3)
Part of the Application Development and Security Fundamentals domain, which makes up ~20% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 2–3 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)
37questions here
8free pages
4concepts
Questions 11–15
- 11
A development team is using a third-party component library that has a known vulnerability. The team is unsure whether to update the library because it may break existing functionality. Which approach best balances security and stability?
Select an answer first - 12
A developer is writing code to handle user authentication. To mitigate the OWASP Top 10 risk of identification and authentication failures, which approach should be taken during development?
Select an answer first - 13
During the design phase of a new web application, the team wants to reduce the risk of injection attacks. Which practice is most effective to incorporate into the development lifecycle?
Select an answer first - 14
A team is developing a web application that handles user authentication. They are implementing a 'remember me' feature that stores a cookie on the user's browser. The security lead warns that the current implementation is vulnerable to session hijacking. Which combination of controls best mitigates the risk?
Select an answer first - 15
Which OWASP Top 10 category describes a risk where an attacker can execute arbitrary commands or queries by sending crafted data to an interpreter?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DSE” is a trademark of its owner, used for identification only.