Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified DevSecOps Engineer

Domain 3Objective 3

Security by Design ECDE Practice Questions (Page 2)

Part of the Code and Build Stage: SAST and Secure Code Review domain, which makes up ~15% of our current practice bank.

44questions here
9free pages
5concepts

Questions 6–10

  1. 6expert · hard

    A company is designing a new internal tool that will access a legacy database. The database administrator wants to give the application a service account with broad permissions to simplify development. Which design principle should the security team advocate for?

    Select an answer first
  2. 7application · medium

    A team is designing a new API that will handle sensitive personal data. During threat modeling, they use the STRIDE model. Which threat category is most directly addressed by implementing rate limiting and input validation?

    Select an answer first
  3. 8application · medium

    A team is conducting a security design review for a new authentication service. The proposed design uses a shared secret stored in the application code. Which of the following is the BEST recommendation to improve the design?

    Select an answer first
  4. 9application · medium

    A team is designing a new REST API that will expose customer data. During the design review, they want to define security requirements. Which of the following is the MOST important requirement to include?

    Select an answer first
  5. 10foundation · easy

    Which statement best describes the core principle of 'Security by Design' in software development?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECDE” is a trademark of its owner, used for identification only.