
EC-CouncilDevSecOps Essentials
Domain 4Objective 4
Continuous Security with Security as Code DSE Practice Questions (Page 6)
Part of the DevSecOps Pipelines and CI/CD Security domain, which makes up ~18% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~9–14 in this domain), expect 2–3 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)
50questions here
10free pages
8concepts
Questions 26–30
- 26
At which stage of a CI/CD pipeline is container image scanning most effectively integrated?
Select an answer first - 27
A team is using Terraform to manage infrastructure and wants to implement automated security testing. They have a set of custom security policies that are specific to their organization. They want to test these policies against their Terraform plans before deployment. They also want to ensure that the policies themselves are tested to avoid false positives. What is the best approach?
Select an answer first - 28
What is the purpose of continuous security monitoring in a DevSecOps environment?
Select an answer first - 29
What is the recommended way to store secrets used in a CI/CD pipeline?
Select an answer first - 30
What is 'drift' in the context of Infrastructure as Code security?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DSE” is a trademark of its owner, used for identification only.