
EC-CouncilCertified DevSecOps Engineer
Domain 3Objective 3
Security by Design ECDE Practice Questions (Page 7)
Part of the Code and Build Stage: SAST and Secure Code Review domain, which makes up ~15% of our current practice bank.
44questions here
9free pages
5concepts
Questions 31–35
- 31
A security architect is reviewing a design for a new authentication service. The design uses a shared secret stored in an environment variable. Which design review finding is most critical?
Select an answer first - 32
A developer proposes that the application's database credentials be stored in the source code for simplicity. Which security principle does this violate?
Select an answer first - 33
During a threat modeling session for a new chat application, the team uses the STRIDE model. They identify a threat where an attacker could modify messages in transit. Which STRIDE category does this threat belong to?
Select an answer first - 34
During a design review for a new user profile feature, the team wants to ensure that users can only view their own data. Which security requirement should be included in the design?
Select an answer first - 35
In the context of Security by Design, what is the primary purpose of integrating security into the initial design phase of the software development lifecycle?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECDE” is a trademark of its owner, used for identification only.