Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilDevSecOps Essentials

Domain 4Objective 4

Continuous Security with Security as Code DSE Practice Questions (Page 2)

Part of the DevSecOps Pipelines and CI/CD Security domain, which makes up ~18% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~9–14 in this domain), expect 2–3 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)

50questions here
10free pages
8concepts

Questions 6–10

  1. 6application · medium

    A DevSecOps team is adopting Policy as Code for their CI/CD pipeline. They want to enforce that all container images deployed to production are scanned for vulnerabilities and that any image with a critical severity finding is blocked. The team maintains the policy in a Git repository and wants the policy itself to be reviewed and versioned. Which approach best meets these requirements?

    Select an answer first
  2. 7application · medium

    A team is integrating security scanning into their CI/CD pipeline. They want to scan the application's source code, its dependencies, and the final container image. The team wants to ensure that the scans run as early as possible in the pipeline. Which stage order should they use?

    Select an answer first
  3. 8foundation · easy

    Which type of automated test is used to verify that infrastructure complies with security policies?

    Select an answer first
  4. 9expert · hard

    A company's CI/CD pipeline uses a service principal to deploy to Azure. The service principal has contributor access to the entire subscription. The security team wants to follow least-privilege principles and reduce the risk of credential compromise. Which change should they make?

    Select an answer first
  5. 10expert · hard

    A company is adopting Infrastructure as Code (IaC) and wants to enforce security policies across multiple teams. They have a mix of Terraform and CloudFormation templates. They want to ensure that all templates comply with the same security policies, but they also want to allow teams to request exceptions for specific resources. The policy engine must be centralized and support both IaC tools. What should they do?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DSE” is a trademark of its owner, used for identification only.