Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified DevSecOps Engineer

Domain 3Objective 3

Security by Design ECDE Practice Questions (Page 1)

Part of the Code and Build Stage: SAST and Secure Code Review domain, which makes up ~15% of our current practice bank.

44questions here
9free pages
5concepts

Questions 1–5

  1. 1foundation · easy

    Which of the following is a common technique used in threat modeling to systematically identify potential attack vectors?

    Select an answer first
  2. 2foundation · easy

    During a security design review, which of the following activities is most likely to be performed?

    Select an answer first
  3. 3application · medium

    A team is designing a new online banking system. During threat modeling, they identify that an attacker could perform a man-in-the-middle attack to intercept session tokens. Which of the following is the MOST effective mitigation to include in the design?

    Select an answer first
  4. 4foundation · easy

    During the design stage, a threat modeling exercise is conducted. What is the primary output of this exercise?

    Select an answer first
  5. 5application · medium

    A team is designing a new e-commerce platform. They want to ensure that if a security control fails, the system does not expose sensitive data. Which design principle should they apply?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECDE” is a trademark of its owner, used for identification only.