
EC-CouncilDevSecOps Essentials
Domain 3Objective 3
Continuous Testing Tools DSE Practice Questions (Page 8)
Part of the DevSecOps Toolchain domain, which makes up ~19% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–15 in this domain), expect 2–3 from this objective — we provide 58 practice questions to prepare you well beyond it. (estimate)
58questions here
12free pages
10concepts
Questions 36–40
- 36
A developer wants to catch security vulnerabilities in their code before pushing to the shared repository. They are working in an IDE and want immediate feedback on potential issues in the code they are writing. Which approach is most aligned with shift-left testing?
Select an answer first - 37
Which practice is an example of shift-left testing?
Select an answer first - 38
A team uses Jenkins for CI/CD and wants security testing tools to automatically run on every code commit and have the results posted back to the developer who made the commit. What is the best way to achieve this?
Select an answer first - 39
An organization uses many open-source libraries in its applications. The security team wants to automatically block builds that include components with known critical vulnerabilities and also flag components with restrictive licenses. Which tool should be integrated into the CI pipeline?
Select an answer first - 40
A company wants to reduce the time between a code change and the discovery of a security vulnerability, and also reduce the cost of fixing it. They plan to run automated security tests as part of the CI pipeline on every commit. What is the primary benefit of this approach?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DSE” is a trademark of its owner, used for identification only.