
EC-CouncilCertified DevSecOps Engineer
Domain 3Objective 3
Security by Design ECDE Practice Questions (Page 8)
Part of the Code and Build Stage: SAST and Secure Code Review domain, which makes up ~15% of our current practice bank.
44questions here
9free pages
5concepts
Questions 36–40
- 36
Which of the following is an example of a well-defined security acceptance criterion?
Select an answer first - 37
During a design review for a new customer-facing web application, the team uses STRIDE to analyze the architecture. They identify a spoofing threat where an attacker could impersonate another user. Which secure architecture pattern most directly mitigates this threat?
Select an answer first - 38
A company is adopting a DevSecOps culture. The security team wants to integrate security into the design phase, but developers are resistant because they feel it slows down delivery. Which of the following is the BEST strategy to overcome this resistance?
Select an answer first - 39
A security architect is conducting a design review of a new payment processing system. The design uses a monolithic application with a single database. The team is concerned about the blast radius if the application is compromised. Which design change would most effectively reduce the blast radius?
Select an answer first - 40
During a security design review of a new microservices architecture, the team discovers that the service-to-service communication uses unauthenticated HTTP. Which of the following is the BEST recommendation to address this issue?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECDE” is a trademark of its owner, used for identification only.