
EC-CouncilCertified DevSecOps Engineer
Domain 3Objective 4
Code Review Strategy ECDE Practice Questions (Page 3)
Part of the Code and Build Stage: SAST and Secure Code Review domain, which makes up ~15% of our current practice bank.
36questions here
8free pages
9concepts
Questions 11–15
- 11
A team is introducing code review into their DevSecOps pipeline. They want to catch issues as early as possible while minimizing disruption. At which point should they first require a security-focused code review?
Select an answer first - 12
How does threat modeling contribute to a code review strategy?
Select an answer first - 13
A security team is reviewing SAST results and finds that the tool has a high false-positive rate on a particular rule. Developers are ignoring all findings from that rule. What is the best course of action?
Select an answer first - 14
A reviewer is using a secure code review checklist on a new feature that allows users to reset passwords. Which checklist item is most critical to verify to prevent account takeover?
Select an answer first - 15
A development team has integrated a SAST tool into their CI pipeline. The tool flags a large number of potential SQL injection vulnerabilities, but the security team suspects many are false positives because the code uses parameterized queries. What is the most effective way to handle this situation?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECDE” is a trademark of its owner, used for identification only.