
EC-CouncilDevSecOps Essentials
Domain 4Objective 2
Key Elements of the DevSecOps Pipeline DSE Practice Questions (Page 7)
Part of the DevSecOps Pipelines and CI/CD Security domain, which makes up ~18% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~9–14 in this domain), expect 2–3 from this objective — we provide 48 practice questions to prepare you well beyond it. (estimate)
48questions here
10free pages
8concepts
Questions 31–35
- 31
What is a key practice for integrating logging into a pipeline for security visibility?
Select an answer first - 32
A DevSecOps team is troubleshooting why developers are not fixing security findings from the pipeline. The findings are posted to a security dashboard, but developers say they do not have time to check it. The team wants to improve the remediation rate without adding more manual steps. What should they do?
Select an answer first - 33
Which of the following is an example of automating a compliance check in a pipeline?
Select an answer first - 34
What is a key measure to secure third-party dependencies used in a build?
Select an answer first - 35
A security team wants to detect a supply-chain attack where a malicious dependency is introduced into a build. They have implemented SCA scanning, but they are concerned that the SCA tool may not catch a newly published malicious package that is not yet in vulnerability databases. What additional measure should they add to the pipeline?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DSE” is a trademark of its owner, used for identification only.