
EC-CouncilDevSecOps Essentials
Domain 5Objective 2
Integrating Secure Coding in the Code Stage DSE Practice Questions (Page 1)
Part of the Implementing DevSecOps Testing and Threat Modeling domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 2–3 from this objective — we provide 56 practice questions to prepare you well beyond it. (estimate)
56questions here
12free pages
12concepts
Questions 1–5
- 1
A developer is writing error-handling code for a web application. The application currently returns detailed stack traces to the client when an exception occurs. Which change is most appropriate?
Select an answer first - 2
A company has a monorepo with multiple services. They want to integrate SAST into the CI pipeline, but the SAST scan takes 30 minutes, which is too long for every commit. They also want to ensure that critical vulnerabilities are not missed. What is the best strategy?
Select an answer first - 3
Which of the following is an example of proper input validation?
Select an answer first - 4
A development team uses a popular open-source library in their application. A new critical vulnerability is disclosed in that library. The team wants to address this in the code stage. Which action is most appropriate?
Select an answer first - 5
In the STRIDE threat model, which category covers an attacker's ability to modify data or code without authorization?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DSE” is a trademark of its owner, used for identification only.