Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified DevSecOps Engineer

Domain 3Objective 3

Security by Design ECDE Practice Questions (Page 7)

Part of the Code and Build Stage: SAST and Secure Code Review domain, which makes up ~15% of our current practice bank.

44questions here
9free pages
5concepts

Questions 31–35

  1. 31application · medium

    A security architect is reviewing a design for a new authentication service. The design uses a shared secret stored in an environment variable. Which design review finding is most critical?

    Select an answer first
  2. 32application · medium

    A developer proposes that the application's database credentials be stored in the source code for simplicity. Which security principle does this violate?

    Select an answer first
  3. 33application · medium

    During a threat modeling session for a new chat application, the team uses the STRIDE model. They identify a threat where an attacker could modify messages in transit. Which STRIDE category does this threat belong to?

    Select an answer first
  4. 34application · medium

    During a design review for a new user profile feature, the team wants to ensure that users can only view their own data. Which security requirement should be included in the design?

    Select an answer first
  5. 35foundation · easy

    In the context of Security by Design, what is the primary purpose of integrating security into the initial design phase of the software development lifecycle?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECDE” is a trademark of its owner, used for identification only.