
EC-CouncilDevSecOps Essentials
Domain 4Objective 4
Continuous Security with Security as Code DSE Practice Questions (Page 3)
Part of the DevSecOps Pipelines and CI/CD Security domain, which makes up ~18% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~9–14 in this domain), expect 2–3 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)
50questions here
10free pages
8concepts
Questions 11–15
- 11
What is the role of a security gate in a CI/CD pipeline?
Select an answer first - 12
A security team is automating compliance tests in the pipeline. They have a policy that requires all API responses to include a specific security header. They want to test this as part of the pipeline. Which type of test should they implement?
Select an answer first - 13
Which principle should guide the use of secrets in CI/CD pipelines?
Select an answer first - 14
A company is deploying a critical application. Their pipeline includes security scans, but they want to add a manual approval step for the security team before production deployment. The team also wants to track how long approvals take. Which approach should they use?
Select an answer first - 15
A company is implementing Policy as Code for their CI/CD pipeline. They have a policy that requires all secrets to be stored in a vault and not in the repository. They want to enforce this policy across all repositories. Which approach should they take?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DSE” is a trademark of its owner, used for identification only.