Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilDevSecOps Essentials

Domain 1Objective 5

Secure Design Principles, Threat Modeling, and Secure Coding DSE Practice Questions (Page 5)

Part of the Application Development and Security Fundamentals domain, which makes up ~20% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 2–3 from this objective — we provide 52 practice questions to prepare you well beyond it. (estimate)

52questions here
11free pages
10concepts

Questions 21–25

  1. 21application · medium

    During a threat modeling session, the team identifies that an attacker could exploit a SQL injection vulnerability in a legacy login form. The form is scheduled to be replaced in six months. The team decides to add a Web Application Firewall (WAF) rule to block suspicious SQL patterns while the code fix is being developed. This is an example of which risk mitigation strategy?

    Select an answer first
  2. 22application · medium

    A web application uses session cookies for user authentication. The security team has noticed that the session ID is predictable because it is generated using a timestamp and the user's IP address. Which change should be made to improve session management security?

    Select an answer first
  3. 23application · medium

    A web application uses session cookies to maintain user login state. The security team wants to reduce the risk of session hijacking via cross-site scripting (XSS). Which cookie attribute is most directly effective?

    Select an answer first
  4. 24application · medium

    A development team is starting a threat modeling exercise for a new mobile banking application. They have identified the user's device, the backend API, and the database as key components. According to the threat modeling process, what should they do immediately after identifying assets and entry points?

    Select an answer first
  5. 25expert · medium

    A development team is fixing a buffer overflow vulnerability in a C++ application that processes network packets. The team must choose a mitigation strategy that balances security with performance. Which approach is most effective?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DSE” is a trademark of its owner, used for identification only.