
EC-CouncilDevSecOps Essentials
Domain 5Objective 4
Integrating RASP and VAPT in Release and Deploy DSE Practice Questions (Page 1)
Part of the Implementing DevSecOps Testing and Threat Modeling domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 2–3 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)
43questions here
9free pages
7concepts
Questions 1–5
- 1
In the software development lifecycle, when is a penetration test (PT) most appropriately conducted?
Select an answer first - 2
A DevOps team wants to automate security testing in their Jenkins pipeline. They currently have a SAST job that runs on every commit. They now want to add a DAST scan against a deployed staging environment and a RASP configuration check before promoting the build to production. The pipeline must fail the build if critical findings are detected. Which pipeline design best achieves this?
Select an answer first - 3
After a release, the RASP console reports a spike in blocked SQL injection attempts against a new feature. The VAPT scan before release did not identify this vulnerability. What is the most appropriate response?
Select an answer first - 4
A company has a policy that all critical vulnerabilities must be fixed within 48 hours. A VAPT scan identifies a critical vulnerability in a legacy component that requires a vendor patch, which will take two weeks to arrive. The application is business-critical and cannot be taken offline. What is the most appropriate interim action?
Select an answer first - 5
Which approach is commonly used to automate vulnerability scanning within a CI/CD pipeline?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DSE” is a trademark of its owner, used for identification only.