
EC-CouncilCertified DevSecOps Engineer
Domain 3Objective 4
Code Review Strategy ECDE Practice Questions (Page 5)
Part of the Code and Build Stage: SAST and Secure Code Review domain, which makes up ~15% of our current practice bank.
36questions here
8free pages
9concepts
Questions 21–25
- 21
A team is reviewing a large legacy codebase that has never been security-reviewed. They have limited time and must prioritize. Which approach is most effective?
Select an answer first - 22
A DevSecOps team runs SAST on a legacy payment application. The scanner flags a SQL injection in a rarely used admin report and a hardcoded API key in a widely used customer-facing module. The team has limited remediation capacity this sprint. Which approach best aligns with risk-based prioritization?
Select an answer first - 23
A security team has a limited budget for fixing vulnerabilities. They have identified a remote code execution (RCE) vulnerability in an internal tool, a cross-site request forgery (CSRF) issue in a public-facing web form, and a low-severity information disclosure in a public API. Which vulnerability should be fixed first?
Select an answer first - 24
A security team has identified a vulnerability in a public-facing web application that allows an attacker to access other users' data by manipulating a request parameter. The vulnerability is in a function that is used by multiple features. The team has limited time to fix it. What should they do?
Select an answer first - 25
A SAST tool reports a potential command injection in a function that builds a shell command from user input. A developer claims it is a false positive because the input is validated earlier. What is the most appropriate next step?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECDE” is a trademark of its owner, used for identification only.