
EC-CouncilDevSecOps Essentials
Domain 1Objective 5
Secure Design Principles, Threat Modeling, and Secure Coding DSE Practice Questions (Page 10)
Part of the Application Development and Security Fundamentals domain, which makes up ~20% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 2–3 from this objective — we provide 52 practice questions to prepare you well beyond it. (estimate)
52questions here
11free pages
10concepts
Questions 46–50
- 46
A company is adopting a DevSecOps culture and wants to integrate security into the software development lifecycle. They currently perform a security review only after the code is fully developed. Which change best reflects a secure SDLC integration?
Select an answer first - 47
When storing user passwords, which of the following is the most secure approach?
Select an answer first - 48
In which phase of the secure software development lifecycle (SDLC) should security requirements such as authentication and encryption be defined?
Select an answer first - 49
A developer is writing a function that builds a SQL query by concatenating user input directly into the statement. The code review team flags this as a SQL injection risk. Which secure coding practice should the developer apply to prevent this vulnerability?
Select an answer first - 50
Which of the following activities is typically performed during the deployment phase of a secure SDLC?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DSE” is a trademark of its owner, used for identification only.