
EC-CouncilCertified DevSecOps Engineer
Domain 3Objective 4
Code Review Strategy ECDE Practice Questions (Page 2)
Part of the Code and Build Stage: SAST and Secure Code Review domain, which makes up ~15% of our current practice bank.
36questions here
8free pages
9concepts
Questions 6–10
- 6
A security team has identified several vulnerabilities in a web application. The vulnerabilities include a SQL injection in a public-facing login form, a cross-site scripting (XSS) issue in an internal admin panel, and a low-severity information disclosure in error messages. The application is about to be released. How should the team prioritize remediation?
Select an answer first - 7
A security reviewer is conducting a threat model for a new feature that allows users to upload files. The feature will store files in a cloud storage service and provide download links. Which code path should be prioritized for review?
Select an answer first - 8
A reviewer is using a secure code review checklist on a new file-upload feature. The code accepts user-supplied filenames and stores files on disk. Which checklist item is most directly relevant to preventing a path traversal vulnerability?
Select an answer first - 9
A DevSecOps team wants to improve accountability in their code review process. Currently, findings are discussed in chat and often forgotten. Which workflow change would most directly ensure that every finding is tracked to resolution?
Select an answer first - 10
A team is about to review a new microservice that handles user profile updates. The threat model identifies that the service accepts JSON input and stores data in a database. Which code path should be prioritized for manual review?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECDE” is a trademark of its owner, used for identification only.