
CiscoCertified Network Professional Security
Domain 3Objective 7
3.7 Describe DevSecOps (Infrastructure as Code Security, CI/CD Pipeline, Container Orchestration, and Secure Software Development) 350-701 Practice Questions (Page 4)
Part of the Cloud Security domain, which accounts for 15% of the 350-701 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 1–2 from this objective — we provide 24 practice questions to prepare you well beyond it. (estimate)
24questions here
5free pages
4concepts
15%of the exam
Questions 16–20
- 16
A security team is implementing a DevSecOps culture in their organization. They want to ensure that developers are accountable for security without creating a bottleneck. Which approach best achieves this?
Select an answer first - 17
A company uses Terraform to manage infrastructure and Kubernetes for container orchestration. They want to ensure that secrets used in both Terraform and Kubernetes are protected. Which approach provides the most secure and centralized solution?
Select an answer first - 18
What is the primary purpose of integrating automated security scanning into a CI/CD pipeline?
Select an answer first - 19
A developer is writing code that handles user input in a web application. They want to prevent SQL injection attacks. Which secure coding practice should they follow?
Select an answer first - 20
A DevOps team uses Terraform to provision cloud resources. Which practice is most directly associated with securing infrastructure as code?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-701” is a trademark of its owner, used for identification only.