
EC-CouncilDevSecOps Essentials
Domain 4Objective 4
Continuous Security with Security as Code DSE Practice Questions (Page 4)
Part of the DevSecOps Pipelines and CI/CD Security domain, which makes up ~18% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~9–14 in this domain), expect 2–3 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)
50questions here
10free pages
8concepts
Questions 16–20
- 16
A startup is building a new CI/CD pipeline and wants to adopt Security as Code principles. They want to ensure that security policies are treated like software code, with version control, code review, and automated testing. Which practice best aligns with this principle?
Select an answer first - 17
What is the purpose of automated security testing in a CI/CD pipeline?
Select an answer first - 18
A DevOps team is building a CI/CD pipeline that deploys to multiple environments (dev, staging, prod). They need to use different credentials for each environment. They want to ensure that the credentials are not accessible to developers who only work on the dev environment, and that the pipeline can rotate credentials without manual intervention. What is the best approach?
Select an answer first - 19
An organization uses AWS CloudFormation to manage infrastructure. They want to prevent developers from accidentally creating publicly accessible S3 buckets. They also want to ensure that any change to the infrastructure is reviewed and tested before deployment. What should they do?
Select an answer first - 20
What is a common framework used for Policy as Code?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DSE” is a trademark of its owner, used for identification only.