
EC-CouncilDevSecOps Essentials
Domain 3Objective 3
Continuous Testing Tools DSE Practice Questions (Page 4)
Part of the DevSecOps Toolchain domain, which makes up ~19% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–15 in this domain), expect 2–3 from this objective — we provide 58 practice questions to prepare you well beyond it. (estimate)
58questions here
12free pages
10concepts
Questions 16–20
- 16
What is the role of automated tests within a CI/CD pipeline?
Select an answer first - 17
A company currently performs security testing only after the application is fully built and deployed to a test environment. They want to reduce the cost and effort of fixing vulnerabilities by identifying them earlier in the development lifecycle. Which strategy should they adopt?
Select an answer first - 18
Which type of testing is best suited for identifying vulnerabilities that only appear when the application is running?
Select an answer first - 19
A team deploys a web application to a staging environment that is not accessible from the public internet. They want to run DAST scans automatically as part of the CI/CD pipeline. What must they configure to enable this?
Select an answer first - 20
A team has a CI pipeline that runs SAST and SCA scans. The scans produce a large number of findings, and developers are ignoring the reports because they are too long and not prioritized. The team wants to improve the feedback loop so that developers focus on the most important issues first. What should they do?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DSE” is a trademark of its owner, used for identification only.