Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilDevSecOps Essentials

Domain 5Objective 3

Integrating SAST, DAST, and IAST in Build and Test DSE Practice Questions (Page 2)

Part of the Implementing DevSecOps Testing and Threat Modeling domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 2–3 from this objective — we provide 41 practice questions to prepare you well beyond it. (estimate)

41questions here
9free pages
7concepts

Questions 6–10

  1. 6expert · hard

    A company is selecting security testing tools for a new project. The application is a single-page application (SPA) with a REST API backend. The team wants to test both the client-side and server-side vulnerabilities. They have a limited budget and need to choose between a commercial SAST tool and a commercial DAST tool. Which approach is most effective?

    Select an answer first
  2. 7expert · hard

    A team is using IAST in their CI/CD pipeline. They notice that IAST is reporting many vulnerabilities that are not reproducible in manual testing. The team suspects that the IAST agent is generating false positives due to the way it instruments the application. What is the most appropriate action?

    Select an answer first
  3. 8expert · hard

    A team wants to run DAST scans in their CI/CD pipeline for a web application that uses a third-party single sign-on (SSO) provider. The DAST tool needs to authenticate to test authenticated pages. The team is concerned about storing credentials in the pipeline configuration. What is the best approach?

    Select an answer first
  4. 9application · medium

    A team is integrating SAST into their Jenkins pipeline. They are concerned about slowing down the build and causing developer frustration. They want to minimize disruption while still catching critical vulnerabilities. Which best practice should they apply?

    Select an answer first
  5. 10application · medium

    A DevOps team wants to automate SAST and DAST scans in their GitLab CI/CD pipeline. They need to ensure that scan results are centrally visible to developers and security teams. Which approach best achieves this?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DSE” is a trademark of its owner, used for identification only.