
EC-CouncilCertified DevSecOps Engineer
Domain 3Objective 1
Static Application Security Testing (SAST) Concepts and Tools ECDE Practice Questions (Page 2)
Part of the Code and Build Stage: SAST and Secure Code Review domain, which makes up ~15% of our current practice bank.
53questions here
11free pages
10concepts
Questions 6–10
- 6
A security team is designing a testing strategy for a web application. They want to detect vulnerabilities that only manifest at runtime, such as authentication bypasses that depend on the application's state or configuration. Which testing approach should they use?
Select an answer first - 7
A security engineer is explaining to a developer why a SAST scan did not detect a cross-site scripting (XSS) vulnerability that was later found in production. The vulnerability only occurs when the application is used with a specific browser configuration. What is the most likely reason SAST missed it?
Select an answer first - 8
What is the primary purpose of Static Application Security Testing (SAST) in the software development lifecycle?
Select an answer first - 9
A security team is implementing a secure code review process. They have an automated SAST tool that scans every commit. The team wants to add a manual code review step that complements the SAST results. Which manual review activity would provide the most value beyond what the SAST tool already detects?
Select an answer first - 10
A team is deciding how to allocate security review effort for a critical payment processing module. They have a SAST tool that scans the code, but they are considering adding a manual code review. The team has limited time and wants to maximize the value of the manual review. Which focus area would provide the most benefit beyond the SAST scan?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECDE” is a trademark of its owner, used for identification only.