
EC-CouncilDevSecOps Essentials
Domain 4Objective 3
Integrating Security into the DevOps Pipeline DSE Practice Questions (Page 8)
Part of the DevSecOps Pipelines and CI/CD Security domain, which makes up ~18% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~9–14 in this domain), expect 2–3 from this objective — we provide 49 practice questions to prepare you well beyond it. (estimate)
49questions here
10free pages
8concepts
Questions 36–40
- 36
A team wants to embed security controls throughout their CI/CD pipeline. They currently have a build stage, a test stage, and a deploy stage. Which set of additions would provide the most comprehensive security coverage?
Select an answer first - 37
A pipeline needs to access an API key to deploy to a cloud environment. The team wants to ensure that the key is not exposed in logs or build output. What is the best practice for handling this secret?
Select an answer first - 38
What is a recommended method for securely storing secrets used in a CI/CD pipeline?
Select an answer first - 39
A team is building a microservices application and wants to add security testing to their pipeline. They have a fast CI process and want to avoid slowing down developers. They also need to catch both code-level and runtime vulnerabilities. Which approach best balances speed and coverage?
Select an answer first - 40
Which tool category is commonly used to perform security checks on Infrastructure as Code templates?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DSE” is a trademark of its owner, used for identification only.