Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified DevSecOps Engineer

Domain 3Objective 4

Code Review Strategy ECDE Practice Questions (Page 4)

Part of the Code and Build Stage: SAST and Secure Code Review domain, which makes up ~15% of our current practice bank.

36questions here
8free pages
9concepts

Questions 16–20

  1. 16expert · hard

    A security review of a critical application finds two issues: a cross-site scripting (XSS) vulnerability in a public-facing search page and a server-side request forgery (SSRF) in an internal admin tool. The SSRF is only accessible to authenticated admins. Which finding should be prioritized?

    Select an answer first
  2. 17expert · hard

    A DevSecOps team is establishing a collaborative review workflow. They want to ensure that findings are not only fixed but also that the process improves over time. Which practice is most important to include?

    Select an answer first
  3. 18application · medium

    A team wants to ensure that code review findings are not ignored. They are using a SAST tool that integrates with their version control system. What is the best way to ensure accountability?

    Select an answer first
  4. 19application · medium

    A team integrates SAST into their CI/CD pipeline. Developers complain that the build fails on many low-severity findings, slowing delivery. The security team wants to keep the gate. Which configuration best balances security and developer velocity?

    Select an answer first
  5. 20application · medium

    A security team wants to measure the effectiveness of their code review process. They want to track whether security findings are being caught early and whether the process is improving over time. Which metric is most useful for this purpose?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECDE” is a trademark of its owner, used for identification only.