Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilDevSecOps Essentials

Domain 4Objective 5

Application Assessments and Penetration Testing DSE Practice Questions (Page 4)

Part of the DevSecOps Pipelines and CI/CD Security domain, which makes up ~18% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~9–14 in this domain), expect 2–3 from this objective — we provide 52 practice questions to prepare you well beyond it. (estimate)

52questions here
11free pages
10concepts

Questions 16–20

  1. 16application · medium

    A security team wants to identify vulnerabilities that are only visible during runtime, such as insecure deserialization, while also pinpointing the exact line of code responsible. They are willing to instrument the application during testing. Which approach should they use?

    Select an answer first
  2. 17expert · hard

    A security team needs to report on the effectiveness of their DevSecOps pipeline to management. They have data on vulnerability counts, remediation times, and scan coverage. Management wants to know if the pipeline is actually reducing risk over time. Which metric would best demonstrate this?

    Select an answer first
  3. 18foundation · easy

    In a DevSecOps pipeline, how is penetration testing typically scheduled?

    Select an answer first
  4. 19expert · hard

    A company is planning a comprehensive security assessment of their web application before a major release. They want to identify vulnerabilities in the source code, test the running application for runtime issues, and check for known vulnerabilities in open-source libraries. They have a limited budget and need to choose the most efficient combination of assessments. Which combination should they use?

    Select an answer first
  5. 20application · medium

    Before developing a new payment processing feature, a security architect wants to systematically identify potential threats, such as spoofing and tampering, and document them for the development team. Which structured technique should they use?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DSE” is a trademark of its owner, used for identification only.