
EC-CouncilDevSecOps Essentials
Domain 4Objective 3
Integrating Security into the DevOps Pipeline DSE Practice Questions (Page 4)
Part of the DevSecOps Pipelines and CI/CD Security domain, which makes up ~18% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~9–14 in this domain), expect 2–3 from this objective — we provide 49 practice questions to prepare you well beyond it. (estimate)
49questions here
10free pages
8concepts
Questions 16–20
- 16
What is the primary benefit of integrating security testing early in the software development lifecycle (shift-left)?
Select an answer first - 17
In a CI/CD pipeline, which type of automated security test is most appropriate for identifying vulnerabilities in the application's source code without executing it?
Select an answer first - 18
Which automated security test is best suited for detecting vulnerabilities in a running web application, such as SQL injection or cross-site scripting?
Select an answer first - 19
A development team uses a CI/CD pipeline that builds a container image, runs unit tests, and then pushes the image to a registry. The security team wants to prevent any image with a critical vulnerability from being deployed to production. Which approach should be implemented?
Select an answer first - 20
A company uses a central artifact repository. They want to ensure that only artifacts that have passed security scans are deployed. However, some artifacts are built by external teams and uploaded directly to the repository. What is the best way to enforce this policy?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DSE” is a trademark of its owner, used for identification only.