
EC-CouncilDevSecOps Essentials
Domain 4Objective 5
Application Assessments and Penetration Testing DSE Practice Questions (Page 10)
Part of the DevSecOps Pipelines and CI/CD Security domain, which makes up ~18% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~9–14 in this domain), expect 2–3 from this objective — we provide 52 practice questions to prepare you well beyond it. (estimate)
52questions here
11free pages
10concepts
Questions 46–50
- 46
A team is adding DAST to their CI/CD pipeline for a web application. The application requires authentication to access most features. The team wants to scan the authenticated areas during the pipeline without storing credentials in plain text in the repository. What should they do?
Select an answer first - 47
Which of the following best describes how IAST tools operate?
Select an answer first - 48
A DevSecOps team is integrating SAST into their CI pipeline. They want to fail the build on critical and high severity findings but allow the pipeline to continue for medium and low findings so developers can review them later. The team also needs to ensure that the SAST scan results are available to the security team for tracking. Which approach should they use?
Select an answer first - 49
Which of the following is a common type of application assessment used in a DevSecOps pipeline?
Select an answer first - 50
Which metric is commonly used to track the effectiveness of a security testing program?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DSE” is a trademark of its owner, used for identification only.