
EC-CouncilDevSecOps Essentials
Domain 4Objective 2
Key Elements of the DevSecOps Pipeline DSE Practice Questions (Page 3)
Part of the DevSecOps Pipelines and CI/CD Security domain, which makes up ~18% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~9–14 in this domain), expect 2–3 from this objective — we provide 48 practice questions to prepare you well beyond it. (estimate)
48questions here
10free pages
8concepts
Questions 11–15
- 11
A team is using a CI/CD pipeline to deploy infrastructure as code to multiple cloud environments (dev, staging, production). They want to ensure that security policies are enforced consistently across all environments. Which approach is most effective?
Select an answer first - 12
An organization is adopting infrastructure as code (IaC) to manage its cloud environments. They want to ensure that security misconfigurations are caught before infrastructure is deployed. The team uses Terraform to provision resources and has a CI pipeline for the IaC code. Which control should they implement in the pipeline?
Select an answer first - 13
Where in a CI/CD pipeline is a static application security testing (SAST) tool most appropriately integrated?
Select an answer first - 14
A team uses infrastructure as code to manage environments. They want to ensure that production environments are immutable and that any change is deployed through the pipeline, not manually. They also want to monitor for drift. Which approach best achieves this?
Select an answer first - 15
What is the primary benefit of automating security checks in a CI/CD pipeline?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DSE” is a trademark of its owner, used for identification only.