
EC-CouncilDevSecOps Essentials
Domain 5Objective 2
Integrating Secure Coding in the Code Stage DSE Practice Questions (Page 5)
Part of the Implementing DevSecOps Testing and Threat Modeling domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 2–3 from this objective — we provide 56 practice questions to prepare you well beyond it. (estimate)
56questions here
12free pages
12concepts
Questions 21–25
- 21
A SAST scan has identified several vulnerabilities in a codebase. The team has limited development resources. Which vulnerabilities should be fixed first?
Select an answer first - 22
A SAST scan identifies several vulnerabilities in a codebase: a SQL injection in a login form, a hardcoded API key, and a minor information disclosure in an error message. The team has limited time before the next release. What is the correct prioritization?
Select an answer first - 23
An organization wants to enforce secure coding standards across multiple development teams. They have different programming languages and frameworks. What is the most effective way to implement this?
Select an answer first - 24
A security audit reveals that the application logs full credit card numbers in plain text. The team must comply with PCI DSS and reduce the risk of data breaches. What is the best remediation?
Select an answer first - 25
During a security code review, a reviewer finds that a developer has used a blacklist-based input validation approach. The reviewer recommends switching to a whitelist approach. Why is this recommendation valid?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DSE” is a trademark of its owner, used for identification only.