
EC-CouncilDevSecOps Essentials
Domain 5Objective 3
Integrating SAST, DAST, and IAST in Build and Test DSE Practice Questions (Page 4)
Part of the Implementing DevSecOps Testing and Threat Modeling domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 2–3 from this objective — we provide 41 practice questions to prepare you well beyond it. (estimate)
41questions here
9free pages
7concepts
Questions 16–20
- 16
What type of vulnerabilities is DAST specifically designed to detect?
Select an answer first - 17
What is the primary benefit of automating SAST, DAST, and IAST scans within a CI/CD pipeline?
Select an answer first - 18
What is the purpose of orchestrating the results from multiple security testing tools in a CI/CD pipeline?
Select an answer first - 19
A DevOps team wants to automate security testing in their GitLab CI/CD pipeline. They have a microservices architecture with multiple services. They want to run SAST on every commit and DAST on the deployed staging environment nightly. What is the best way to orchestrate these scans?
Select an answer first - 20
A team is developing a financial application with strict compliance requirements. They have a large existing test suite that covers many business logic paths. They want to integrate IAST to detect vulnerabilities that require specific user roles and data conditions. However, the test suite runs in parallel to reduce execution time. What is the most important consideration when configuring IAST in this environment?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DSE” is a trademark of its owner, used for identification only.