
EC-CouncilDevSecOps Essentials
Domain 4Objective 5
Application Assessments and Penetration Testing DSE Practice Questions (Page 2)
Part of the DevSecOps Pipelines and CI/CD Security domain, which makes up ~18% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~9–14 in this domain), expect 2–3 from this objective — we provide 52 practice questions to prepare you well beyond it. (estimate)
52questions here
11free pages
10concepts
Questions 6–10
- 6
Which factor is most important when prioritizing vulnerabilities for remediation?
Select an answer first - 7
A development team uses many open-source libraries in a Node.js project. They want to automatically detect known vulnerabilities in those libraries and also check for license compliance before each release. Which tool should they add to their CI pipeline?
Select an answer first - 8
A team is deploying a web application to a staging environment. They want to run DAST as part of the pipeline to identify vulnerabilities before production release. The DAST scan requires the application to be running and accessible. At which stage should they run the DAST scan?
Select an answer first - 9
A DevSecOps team uses SAST and SCA in their pipeline. The SAST tool reports a medium-severity vulnerability in the application code, and the SCA tool reports a high-severity vulnerability in a widely used open-source library. The team has limited development capacity. Which vulnerability should they address first?
Select an answer first - 10
A company is developing a new customer-facing web application. They want to identify vulnerabilities early in development and also validate that the deployed application is secure before launch. Which combination of assessment types should they include in their DevSecOps pipeline?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DSE” is a trademark of its owner, used for identification only.