Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilDevSecOps Essentials

Domain 5Objective 3

Integrating SAST, DAST, and IAST in Build and Test DSE Practice Questions (Page 7)

Part of the Implementing DevSecOps Testing and Threat Modeling domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 2–3 from this objective — we provide 41 practice questions to prepare you well beyond it. (estimate)

41questions here
9free pages
7concepts

Questions 31–35

  1. 31foundation · easy

    Which practice is a best practice for integrating security testing tools into a CI/CD pipeline to minimize disruption?

    Select an answer first
  2. 32foundation · easy

    What is a recommended best practice for handling scan results in a CI/CD pipeline to maximize coverage while minimizing disruption?

    Select an answer first
  3. 33expert · hard

    A team wants to integrate SAST, DAST, and IAST into their CI/CD pipeline. They have a limited number of build agents and want to minimize the impact on pipeline duration. They also need to ensure that results are correlated for effective remediation. Which orchestration approach is best?

    Select an answer first
  4. 34foundation · easy

    In a CI/CD pipeline, at which stage is Static Application Security Testing (SAST) most commonly integrated to identify vulnerabilities in source code early?

    Select an answer first
  5. 35foundation · easy

    What is the primary purpose of integrating a SAST tool into the CI/CD build pipeline?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DSE” is a trademark of its owner, used for identification only.