Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilDevSecOps Essentials

Domain 6Objective 4

Integrating Logging, Monitoring, and Alerting DSE Practice Questions (Page 2)

Part of the DevSecOps Monitoring and Feedback domain, which makes up ~15% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 2–2 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)

47questions here
10free pages
5concepts

Questions 6–10

  1. 6expert · hard

    A financial services company runs a trading application that experiences extreme load volatility. The operations team has set static thresholds for CPU and memory, but during peak trading hours, these thresholds are often exceeded, causing many false alerts. Conversely, during off-peak hours, genuine issues may not trigger alerts because the baseline is lower. The team wants to reduce false positives while maintaining sensitivity to real anomalies. Which approach is most effective?

    Select an answer first
  2. 7expert · hard

    A DevSecOps team notices that the same type of incident (database connection exhaustion) has occurred three times in the past month. Each time, the on-call engineer manually restarted the database and the alert was resolved. The team wants to prevent recurrence and improve the system. Which action is most aligned with a feedback loop?

    Select an answer first
  3. 8expert · hard

    A large organization has separate teams for security and operations. The security team uses a SIEM for log analysis, while the operations team uses a separate monitoring tool for metrics and alerts. During a recent incident, the two teams could not correlate security events with performance data, delaying response. The organization wants to improve collaboration and response time without replacing both tools entirely. Which approach best addresses this?

    Select an answer first
  4. 9application · medium

    A company is migrating a legacy monolithic application to a containerized microservices architecture. The security team wants to maintain visibility into user authentication and authorization events across all services. What is the most effective approach?

    Select an answer first
  5. 10application · medium

    A security analyst needs to investigate a suspected data breach. The company has logs from the firewall, the application server, and the database. Which logging practice is most important for the investigation?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DSE” is a trademark of its owner, used for identification only.