
EC-CouncilDevSecOps Essentials
Domain 1Objective 5
Secure Design Principles, Threat Modeling, and Secure Coding DSE Practice Questions (Page 6)
Part of the Application Development and Security Fundamentals domain, which makes up ~20% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 2–3 from this objective — we provide 52 practice questions to prepare you well beyond it. (estimate)
52questions here
11free pages
10concepts
Questions 26–30
- 26
A development team is implementing authentication for a new application. They want to store user passwords securely. Which approach is the most secure practice for password storage?
Select an answer first - 27
A security team is prioritizing threats identified for a new online banking system. They have identified two threats: Threat A has a high likelihood but low impact, and Threat B has a low likelihood but high impact. The team has limited resources and must choose which to mitigate first. Which approach is most appropriate?
Select an answer first - 28
During a threat modeling exercise, the team lists all the ways an attacker could interact with the system, such as the login page, API endpoints, and file upload functionality. Which element of the threat modeling process are they identifying?
Select an answer first - 29
A web application displays user-generated comments on a page. To prevent cross-site scripting (XSS) attacks, what should the application do before rendering the comments?
Select an answer first - 30
A developer is writing code that copies user input into a fixed-size buffer without checking the length. Which common coding vulnerability is the developer at risk of introducing?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DSE” is a trademark of its owner, used for identification only.