
EC-CouncilCertified DevSecOps Engineer
Domain 3Objective 4
Code Review Strategy ECDE Practice Questions (Page 7)
Part of the Code and Build Stage: SAST and Secure Code Review domain, which makes up ~15% of our current practice bank.
36questions here
8free pages
9concepts
Questions 31–35
- 31
A team is about to review a microservices-based application. The application includes a user service, a payment service, and an inventory service. The team has limited time for manual review. Which service should be prioritized for manual review?
Select an answer first - 32
A DevSecOps team is defining the scope and timing of code review in their pipeline. They want to catch vulnerabilities as early as possible while minimizing the impact on developers. Which approach is most appropriate?
Select an answer first - 33
Which statement best describes the scope of a code review in a DevSecOps context?
Select an answer first - 34
A team is creating a secure code review checklist for a Java web application. The checklist should cover common vulnerability categories. Which set of items is most appropriate for the checklist?
Select an answer first - 35
A development team wants to establish a collaborative code review workflow. They want to ensure that all security findings are tracked and resolved before code is merged. Which workflow best achieves this?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECDE” is a trademark of its owner, used for identification only.