
EC-CouncilDevSecOps Essentials
Domain 4Objective 3
Integrating Security into the DevOps Pipeline DSE Practice Questions (Page 5)
Part of the DevSecOps Pipelines and CI/CD Security domain, which makes up ~18% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~9–14 in this domain), expect 2–3 from this objective — we provide 49 practice questions to prepare you well beyond it. (estimate)
49questions here
10free pages
8concepts
Questions 21–25
- 21
Which practice is an example of integrating compliance checks into a CI/CD pipeline?
Select an answer first - 22
A startup wants to reduce the cost and effort of fixing security vulnerabilities. Currently, they only run security scans after the application is deployed to staging. What change would best align with shift-left security?
Select an answer first - 23
A pipeline promotes a build artifact from a test environment to production. The security team wants to ensure that only artifacts that have passed all security checks are promoted. What is the best way to enforce this?
Select an answer first - 24
A team is adopting Infrastructure as Code (IaC) to deploy cloud resources. They want to prevent misconfigurations such as open security groups or unencrypted storage from reaching production. Which practice should they integrate into their pipeline?
Select an answer first - 25
Which practice best exemplifies a shift-left approach to security?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DSE” is a trademark of its owner, used for identification only.