
EC-CouncilDevSecOps Essentials
Domain 4Objective 1
Role of DevSecOps in the CI/CD Pipeline DSE Practice Questions (Page 7)
Part of the DevSecOps Pipelines and CI/CD Security domain, which makes up ~18% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~9–14 in this domain), expect 2–3 from this objective — we provide 48 practice questions to prepare you well beyond it. (estimate)
48questions here
10free pages
7concepts
Questions 31–35
- 31
What is a key measure to secure the CI/CD pipeline itself against unauthorized changes?
Select an answer first - 32
A team is using multiple security tools in their CI/CD pipeline. They are receiving too many false positives, causing developers to ignore the results. Which strategy is most effective to improve the signal-to-noise ratio?
Select an answer first - 33
A development team uses a Jenkins pipeline to build and deploy a Java application. The security team wants to ensure that known vulnerable dependencies are caught before the application is packaged into an artifact. Which stage-level integration best achieves this?
Select an answer first - 34
A team is migrating from a monthly release cycle to continuous delivery. They want to ensure that every change that reaches production has passed security checks, but they also want to avoid slowing down the pipeline. Which strategy best balances speed and security?
Select an answer first - 35
A team is setting up a CI/CD pipeline for a containerized application. They want to ensure that the container image is secure before it is deployed. Which security control should be integrated at the container build stage?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DSE” is a trademark of its owner, used for identification only.