
EC-CouncilDevSecOps Essentials
Domain 1Objective 4
Common Application Security Risks and OWASP Top 10 DSE Practice Questions (Page 8)
Part of the Application Development and Security Fundamentals domain, which makes up ~20% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 2–3 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)
37questions here
8free pages
4concepts
Questions 36–37
- 36
A security team is introducing a new application security program. They plan to use the OWASP Top 10 as the basis for their secure coding standards and training. Which statement best describes the appropriate use of the OWASP Top 10 in this context?
Select an answer first - 37
A developer is implementing a login form. The current code uses a simple comparison of the username and password against a database. The security team wants to implement multi-factor authentication (MFA) to reduce the risk of credential stuffing. However, the product owner is concerned that MFA will reduce user adoption. Which approach best balances security and usability?
Select an answer first
Finished these 2 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to DSE
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DSE” is a trademark of its owner, used for identification only.