
EC-CouncilDevSecOps Essentials
Domain 4Objective 5
Application Assessments and Penetration Testing DSE Practice Questions (Page 9)
Part of the DevSecOps Pipelines and CI/CD Security domain, which makes up ~18% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~9–14 in this domain), expect 2–3 from this objective — we provide 52 practice questions to prepare you well beyond it. (estimate)
52questions here
11free pages
10concepts
Questions 41–45
- 41
A team discovers that a widely used open-source library in their application has a critical vulnerability. They want to automatically identify all projects using the affected version and block builds until the library is updated. What should they implement?
Select an answer first - 42
In a CI/CD pipeline, at which stage is SAST typically integrated?
Select an answer first - 43
What is the primary purpose of vulnerability management after an assessment?
Select an answer first - 44
What does a Static Application Security Testing (SAST) tool primarily analyze?
Select an answer first - 45
A team uses multiple security tools in their CI/CD pipeline: SAST, DAST, SCA, and IAST. Each tool produces its own report in a different format. The security team wants a single consolidated view of all findings to track remediation. What should the team do?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DSE” is a trademark of its owner, used for identification only.