
EC-CouncilDevSecOps Essentials
Domain 4Objective 5
Application Assessments and Penetration Testing DSE Practice Questions (Page 3)
Part of the DevSecOps Pipelines and CI/CD Security domain, which makes up ~18% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~9–14 in this domain), expect 2–3 from this objective — we provide 52 practice questions to prepare you well beyond it. (estimate)
52questions here
11free pages
10concepts
Questions 11–15
- 11
What is the primary characteristic of Interactive Application Security Testing (IAST)?
Select an answer first - 12
A team integrates SAST, DAST, and SCA into their CI pipeline. They notice that the pipeline is becoming slow and developers are complaining about long feedback times. They want to maintain security coverage while improving pipeline performance. What is the best approach?
Select an answer first - 13
What does a Dynamic Application Security Testing (DAST) tool do?
Select an answer first - 14
A development team is evaluating security testing tools for a Java application that is deployed to a test environment. They need to identify vulnerabilities that occur during runtime, such as SQL injection and authentication flaws, and also want to trace them back to the specific source code lines. Which tool type should they choose?
Select an answer first - 15
What is a common way to integrate security testing tools into a CI/CD pipeline?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DSE” is a trademark of its owner, used for identification only.