
EC-CouncilDevSecOps Essentials
Domain 5Objective 2
Integrating Secure Coding in the Code Stage DSE Practice Questions (Page 11)
Part of the Implementing DevSecOps Testing and Threat Modeling domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 2–3 from this objective — we provide 56 practice questions to prepare you well beyond it. (estimate)
56questions here
12free pages
12concepts
Questions 51–55
- 51
During a code review, a developer notices that the application's error handler returns the full stack trace to the user and logs the user's password in plain text. What is the most appropriate remediation?
Select an answer first - 52
A team has integrated a SAST tool into their CI pipeline. The tool reports a high number of false positives. What is the best way to handle this?
Select an answer first - 53
When prioritizing vulnerabilities for remediation, which factor should be considered first?
Select an answer first - 54
A security-focused code review is being conducted for a new feature that handles user authentication. The reviewer notices that the code uses a custom password hashing algorithm. What should the reviewer recommend?
Select an answer first - 55
What is the primary function of a Static Application Security Testing (SAST) tool?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DSE” is a trademark of its owner, used for identification only.