Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified DevSecOps Engineer

Domain 3Objective 1

Static Application Security Testing (SAST) Concepts and Tools ECDE Practice Questions (Page 6)

Part of the Code and Build Stage: SAST and Secure Code Review domain, which makes up ~15% of our current practice bank.

53questions here
11free pages
10concepts

Questions 26–30

  1. 26foundation · easy

    Which type of vulnerability is DAST more likely to detect than SAST?

    Select an answer first
  2. 27foundation · easy

    What is a key weakness of automated SAST tools compared to manual code review?

    Select an answer first
  3. 28application · easy

    A startup is developing a mobile application backend in Python. The team wants to identify security vulnerabilities as early as possible in the development lifecycle. They are considering when to run a SAST scan. Which point in the development process would provide the earliest meaningful feedback while still being practical?

    Select an answer first
  4. 29foundation · easy

    What is a common limitation of SAST tools?

    Select an answer first
  5. 30application · medium

    A SAST scan of a web application reports a cross-site scripting (XSS) vulnerability in a function that outputs user input. The development team reviews the code and determines that the output is HTML-encoded before being rendered. The SAST tool does not recognize the encoding function as a sanitizer. What should the team do?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECDE” is a trademark of its owner, used for identification only.