Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilDevSecOps Essentials

Domain 4Objective 4

Continuous Security with Security as Code DSE Practice Questions (Page 9)

Part of the DevSecOps Pipelines and CI/CD Security domain, which makes up ~18% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~9–14 in this domain), expect 2–3 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)

50questions here
10free pages
8concepts

Questions 41–45

  1. 41foundation · easy

    What is a key component of a feedback loop in continuous security monitoring?

    Select an answer first
  2. 42application · medium

    A security team wants to automate compliance checks as part of the CI/CD pipeline. They have a set of security controls defined in a policy file. The team wants to ensure that the policy file itself is tested before it is used to enforce controls. Which practice should they adopt?

    Select an answer first
  3. 43expert · hard

    A large enterprise has a CI/CD pipeline that deploys a critical application. They have a security gate that fails the build if a SAST scan finds any critical vulnerability. However, a recent release was blocked because the SAST tool reported a false positive. The team wants to reduce the impact of false positives while maintaining a strong security posture. They also need to ensure that any override is documented and approved by the security team. What is the best approach?

    Select an answer first
  4. 44application · medium

    A DevSecOps team wants to continuously improve their security posture. They have implemented security scanning in the pipeline and want to track metrics such as vulnerability density and time-to-remediate. Which approach should they take?

    Select an answer first
  5. 45application · medium

    An organization uses Terraform to manage its cloud infrastructure. They want to ensure that all Terraform modules enforce encryption for storage accounts and that any deviation is caught before deployment. The team wants to follow Security as Code principles. Which combination of practices should they implement?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DSE” is a trademark of its owner, used for identification only.