
EC-CouncilDevSecOps Essentials
Domain 4Objective 3
Integrating Security into the DevOps Pipeline DSE Practice Questions (Page 9)
Part of the DevSecOps Pipelines and CI/CD Security domain, which makes up ~18% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~9–14 in this domain), expect 2–3 from this objective — we provide 49 practice questions to prepare you well beyond it. (estimate)
49questions here
10free pages
8concepts
Questions 41–45
- 41
A company's CI/CD pipeline needs to deploy to a cloud environment. The pipeline must use a service account credential to authenticate. The security team wants to ensure the credential is not stored in the repository or visible in logs. What is the recommended approach?
Select an answer first - 42
A startup is building a new application and wants to adopt a DevSecOps approach. They have limited security staff and want to minimize the cost of fixing vulnerabilities. Which strategy should they prioritize?
Select an answer first - 43
What is the purpose of a security gate in a CI/CD pipeline?
Select an answer first - 44
How can a pipeline securely inject a secret into an application at runtime without exposing it in logs?
Select an answer first - 45
A team wants to embed security controls throughout their CI/CD pipeline. They have already added SAST in the build stage. Which additional control should they add to cover the artifact and deployment stages?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DSE” is a trademark of its owner, used for identification only.