
EC-CouncilDevSecOps Essentials
Domain 5Objective 2
Integrating Secure Coding in the Code Stage DSE Practice Questions (Page 8)
Part of the Implementing DevSecOps Testing and Threat Modeling domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 2–3 from this objective — we provide 56 practice questions to prepare you well beyond it. (estimate)
56questions here
12free pages
12concepts
Questions 36–40
- 36
A developer is writing a function that queries a database using user input. The developer wants to follow secure coding principles. Which approach is the most secure?
Select an answer first - 37
A web application uses role-based access control (RBAC). A security review finds that a low-privileged user can access an admin endpoint by changing a parameter in the URL. The application uses a session cookie for authentication. What is the most likely cause and the best fix?
Select an answer first - 38
A developer is implementing a feature that allows users to upload profile pictures. The application will store the files on the server and serve them back to users. Which combination of controls is most important to prevent security issues?
Select an answer first - 39
During a security code review, a reviewer notices that a developer has concatenated user input directly into a SQL query string. Which issue should the reviewer flag as the highest priority?
Select an answer first - 40
A team is building a public-facing web application that allows users to upload profile pictures. During threat modeling, they identify a risk of stored XSS via SVG files. The team wants to allow image uploads but prevent XSS. They also need to keep the feature user-friendly and avoid breaking legitimate images. What is the best approach?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DSE” is a trademark of its owner, used for identification only.