
EC-CouncilCertified DevSecOps Engineer
Domain 3Objective 3
Security by Design ECDE Practice Questions (Page 5)
Part of the Code and Build Stage: SAST and Secure Code Review domain, which makes up ~15% of our current practice bank.
44questions here
9free pages
5concepts
Questions 21–25
- 21
What is the purpose of defining security requirements and acceptance criteria for a software feature?
Select an answer first - 22
During a security design review of a new application, the team identifies that the design uses a single shared database account for all services. The security lead wants to recommend a change. However, the development team argues that separate accounts would increase operational overhead. Which of the following is the BEST recommendation that addresses the security concern while minimizing operational impact?
Select an answer first - 23
During the design review of a new file upload feature, the team identifies that users can upload files that are later served back to other users. The security lead wants to define a security requirement with clear acceptance criteria. Which requirement statement is the MOST testable and actionable?
Select an answer first - 24
A team is designing a new feature that allows users to share files. The security team wants to ensure that security requirements are defined early. Which of the following is the MOST important security requirement to include?
Select an answer first - 25
In the context of secure architecture patterns, what does the principle of 'least privilege' require?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECDE” is a trademark of its owner, used for identification only.