Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilDevSecOps Essentials

Domain 1Objective 5

Secure Design Principles, Threat Modeling, and Secure Coding DSE Practice Questions (Page 9)

Part of the Application Development and Security Fundamentals domain, which makes up ~20% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 2–3 from this objective — we provide 52 practice questions to prepare you well beyond it. (estimate)

52questions here
11free pages
10concepts

Questions 41–45

  1. 41application · medium

    A DevSecOps team is conducting a threat modeling exercise for a new microservices-based order processing system. The system accepts orders via a public REST API, processes payments through a third-party gateway, and stores order data in a private database. The team has identified the API endpoint as an entry point and the database as an asset. What should they do next in the threat modeling process?

    Select an answer first
  2. 42foundation · easy

    Which of the following is a best practice for secure session management in a web application?

    Select an answer first
  3. 43foundation · easy

    Which of the following is a common coding vulnerability that occurs when untrusted data is sent to an interpreter as part of a command or query, such as SQL or OS commands?

    Select an answer first
  4. 44expert · hard

    A DevSecOps team is threat modeling a legacy application that processes sensitive customer data. They have identified a critical vulnerability in the authentication module that could allow account takeover. The team has limited budget and must choose between two mitigations: (A) implementing multi-factor authentication (MFA) for all users, or (B) rewriting the authentication module with secure coding practices. The application is scheduled for a major rewrite in six months. Which approach is the most appropriate risk mitigation strategy given the constraints?

    Select an answer first
  5. 45foundation · easy

    A security team creates a diagram that starts with a root goal (e.g., 'steal user data') and branches into sub-goals (e.g., 'gain database access', 'exploit SQL injection') to visualize different attack paths. Which threat identification technique is this?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DSE” is a trademark of its owner, used for identification only.