
EC-CouncilDevSecOps Essentials
Domain 3Objective 3
Continuous Testing Tools DSE Practice Questions (Page 9)
Part of the DevSecOps Toolchain domain, which makes up ~19% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–15 in this domain), expect 2–3 from this objective — we provide 58 practice questions to prepare you well beyond it. (estimate)
58questions here
12free pages
10concepts
Questions 41–45
- 41
What does test coverage measure in the context of continuous testing?
Select an answer first - 42
A company uses many open-source libraries in their Node.js application. They want to automatically detect known vulnerabilities in these libraries and also check for license compliance before each release. Which tool should they integrate into their pipeline?
Select an answer first - 43
What is the primary characteristic of Dynamic Application Security Testing (DAST)?
Select an answer first - 44
A team wants to enforce a minimum code coverage of 80% and no critical security vulnerabilities in their CI pipeline. However, they are concerned that a strict quality gate might block urgent hotfixes that need to go out quickly. They want to balance security with delivery speed. What is the best approach?
Select an answer first - 45
A team uses GitHub for version control, Jenkins for CI, and Artifactory for storing build artifacts. They want security scans to run automatically whenever a developer pushes code. Which integration approach is most effective?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DSE” is a trademark of its owner, used for identification only.