
EC-CouncilDevSecOps Essentials
Domain 1Objective 4
Common Application Security Risks and OWASP Top 10 DSE Practice Questions (Page 5)
Part of the Application Development and Security Fundamentals domain, which makes up ~20% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 2–3 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)
37questions here
8free pages
4concepts
Questions 21–25
- 21
A developer is building a file upload feature for a document management system. The system stores files on disk and later serves them to authenticated users. The developer wants to prevent an attacker from uploading a malicious executable that could be run on the server. Which combination of controls is most effective?
Select an answer first - 22
A company is developing a web application that uses a SQL database. The development team is considering two approaches to prevent SQL injection: (1) use parameterized queries, and (2) use an ORM (Object-Relational Mapping) framework. The team is concerned that parameterized queries are too verbose and ORM might hide complex queries. Which approach is more secure and why?
Select an answer first - 23
A company's web application allows users to reset their passwords by answering security questions. During a penetration test, the tester discovers that the application reveals whether a username exists during the reset process, and that the security questions have a limited set of possible answers (e.g., 'What is your favorite color?'). Which OWASP Top 10 category is most directly exploited, and what is the best remediation?
Select an answer first - 24
Which statement best describes the scope of the OWASP Top 10?
Select an answer first - 25
A security manager is introducing OWASP Top 10 to a development team that has never used it. The manager wants to set realistic expectations about what the list provides. Which statement accurately describes the purpose and scope of the OWASP Top 10?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DSE” is a trademark of its owner, used for identification only.