
EC-CouncilDevSecOps Essentials
Domain 4Objective 4
Continuous Security with Security as Code DSE Practice Questions (Page 7)
Part of the DevSecOps Pipelines and CI/CD Security domain, which makes up ~18% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~9–14 in this domain), expect 2–3 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)
50questions here
10free pages
8concepts
Questions 31–35
- 31
A security team wants to adopt Security as Code but faces resistance from developers who say it will slow down their delivery. The team wants to demonstrate the value of Security as Code by showing how it can reduce the number of security issues in production. They also want to ensure that security policies are continuously improved. What is the best way to gain developer buy-in?
Select an answer first - 32
A development team is migrating their CI/CD pipeline to a new platform. They currently store database credentials in plain text in the pipeline configuration file, which is stored in a Git repository. They need to eliminate this risk while keeping the pipeline functional and ensuring that only the pipeline service account can access the credentials. What should they do?
Select an answer first - 33
A DevOps team is designing a CI/CD pipeline for a critical application. They want to ensure that no deployment occurs if a SAST scan finds a critical vulnerability, but they also want to allow the security team to approve a deployment in exceptional cases. The approval must be recorded and traceable. What should they configure?
Select an answer first - 34
A team is setting up a CI/CD pipeline for a microservices application. They need to pass a database password to a deployment job. The password is stored in a secrets manager. They want to ensure that the password is not exposed in logs or build artifacts. What is the best practice?
Select an answer first - 35
A platform team manages a shared CI/CD pipeline used by multiple product teams. They need to enforce a company-wide policy that no container image with critical vulnerabilities can be deployed, but they also want to allow teams to override the block for a specific image with a documented exception. The policy must be reviewed and versioned like code. What should they implement?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DSE” is a trademark of its owner, used for identification only.