Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilDevSecOps Essentials

Domain 6Objective 5

Integrating a Continuous Feedback Loop DSE Practice Questions (Page 5)

Part of the DevSecOps Monitoring and Feedback domain, which makes up ~15% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 2–2 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)

50questions here
10free pages
8concepts

Questions 21–25

  1. 21expert · hard

    A DevSecOps team is designing a CI/CD pipeline for a critical application. They want to include security feedback gates, but they have two conflicting requirements: the pipeline must not slow down the development cycle, and it must catch high-severity vulnerabilities before production. They have a limited budget for compute resources. Which approach best meets both requirements?

    Select an answer first
  2. 22foundation · easy

    Why is it important to prioritize feedback items in a DevSecOps environment?

    Select an answer first
  3. 23application · medium

    A DevSecOps team wants to automatically fail a build in the CI/CD pipeline when a high-severity vulnerability is found in a container image. The pipeline already runs a container security scanner that outputs a JSON report. What should the team implement to achieve this without manual intervention?

    Select an answer first
  4. 24expert · hard

    A DevSecOps team collects feedback from multiple sources: SAST, DAST, dependency scans, and production monitoring. They notice that the number of open vulnerabilities is increasing, but the number of critical vulnerabilities is decreasing. The team has limited remediation resources. How should they prioritize their efforts?

    Select an answer first
  5. 25application · medium

    A security scan in the CI/CD pipeline has been failing the build for the same critical vulnerability for two weeks. Developers keep fixing it locally, but it reappears because the vulnerable library is pulled from a shared repository. What is the most effective way to close the loop on this recurring feedback?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DSE” is a trademark of its owner, used for identification only.