
EC-CouncilDevSecOps Essentials
Domain 5Objective 2
Integrating Secure Coding in the Code Stage DSE Practice Questions (Page 7)
Part of the Implementing DevSecOps Testing and Threat Modeling domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 2–3 from this objective — we provide 56 practice questions to prepare you well beyond it. (estimate)
56questions here
12free pages
12concepts
Questions 31–35
- 31
A developer needs to encrypt sensitive data before storing it in a database. Which approach is most secure?
Select an answer first - 32
A developer is writing logging code for a web application. They want to log security-relevant events, such as login failures. Which practice is most appropriate?
Select an answer first - 33
A team is designing a new microservice that processes user-uploaded files. During threat modeling, they identify that an attacker could upload a malicious file that is later executed on the server. Which mitigation should be applied at the code stage?
Select an answer first - 34
A development team is building a web application that accepts user-supplied search terms and displays them in an HTML results page. A SAST scan flags a potential cross-site scripting (XSS) issue. The team wants to remediate this in the code stage. Which remediation approach is most effective?
Select an answer first - 35
A team wants to integrate security testing into their CI/CD pipeline. They currently have unit tests and a build step. They want to catch vulnerabilities as early as possible without slowing down the pipeline significantly. What should they add first?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DSE” is a trademark of its owner, used for identification only.