Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilDevSecOps Essentials

Domain 1Objective 6

SAST and DAST Testing DSE Practice Questions (Page 4)

Part of the Application Development and Security Fundamentals domain, which makes up ~20% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 2–3 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)

44questions here
9free pages
6concepts

Questions 16–20

  1. 16application · medium

    A security team is planning to implement both SAST and DAST in their organization. They have limited budget and want to maximize the value of their security testing. The team has a mix of new and legacy applications. Which strategy is most cost-effective and comprehensive?

    Select an answer first
  2. 17application · medium

    A development team is adopting a security testing strategy. They want to catch vulnerabilities as early as possible in the CI pipeline, before the application is deployed. However, they also need to identify runtime issues such as authentication bypasses that only appear when the application is fully running. Which combination of testing approaches should they implement?

    Select an answer first
  3. 18expert · hard

    A DevOps team is integrating SAST into their CI/CD pipeline. They have multiple applications with different programming languages and frameworks. The team wants to standardize the SAST process across all applications while allowing for language-specific rules. What is the best way to achieve this?

    Select an answer first
  4. 19expert · hard

    A security team is planning to run DAST on a web application that has a complex workflow involving multiple steps and stateful sessions. The DAST tool they are using is not able to automatically navigate the workflow. What is the best way to ensure the DAST scan covers the entire application?

    Select an answer first
  5. 20foundation · easy

    Which of the following is a best practice for combining SAST and DAST in a DevSecOps pipeline?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DSE” is a trademark of its owner, used for identification only.