
EC-CouncilCertified DevSecOps Engineer
Domain 3Objective 3
Security by Design ECDE Practice Questions (Page 9)
Part of the Code and Build Stage: SAST and Secure Code Review domain, which makes up ~15% of our current practice bank.
44questions here
9free pages
5concepts
Questions 41–44
- 41
A team is designing a new feature that allows users to export their personal data. The threat model identifies that an attacker could request another user's data by manipulating the export request. The team must define a security requirement with acceptance criteria. Which requirement is the MOST effective?
Select an answer first - 42
A product owner wants to add a 'remember me' feature to a web application. The security team needs to define acceptance criteria for this feature. Which acceptance criterion is most security-relevant?
Select an answer first - 43
A product team is designing a new mobile app that will store user health data. The security team wants to define acceptance criteria for data protection. Which criterion is most important to include?
Select an answer first - 44
A company is designing a new system that will store sensitive customer data. The security architect wants to apply the principle of least privilege to the database access. Which of the following is the BEST approach?
Select an answer first
Finished these 4 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to ECDE
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECDE” is a trademark of its owner, used for identification only.