
EC-CouncilDevSecOps Essentials
Domain 6Objective 3
Integrating Compliance as Code (CaC) DSE Practice Questions (Page 2)
Part of the DevSecOps Monitoring and Feedback domain, which makes up ~15% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 2–2 from this objective — we provide 35 practice questions to prepare you well beyond it. (estimate)
35questions here
7free pages
7concepts
Questions 6–10
- 6
What is the primary purpose of automated compliance reporting in a DevSecOps environment?
Select an answer first - 7
A financial technology company must provide its compliance team with a self-service dashboard to view the compliance status of all AWS accounts in their organization. They use AWS Organizations and have enabled AWS Config in each account. What is the most efficient way to centralize compliance visibility?
Select an answer first - 8
Why is an audit trail important in Compliance as Code?
Select an answer first - 9
How does automating compliance validation in a CI/CD pipeline improve the delivery process?
Select an answer first - 10
A company uses Ansible to manage its infrastructure and has a compliance policy that requires all servers to have a specific security patch installed. The policy is codified as an Ansible playbook that checks for the patch and installs it if missing. The playbook is run nightly. A recent audit found that some servers are missing the patch, even though the playbook ran successfully. What is the most likely cause of this compliance drift?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DSE” is a trademark of its owner, used for identification only.