
EC-CouncilDevSecOps Essentials
Domain 1Objective 6
SAST and DAST Testing DSE Practice Questions (Page 6)
Part of the Application Development and Security Fundamentals domain, which makes up ~20% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 2–3 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)
44questions here
9free pages
6concepts
Questions 26–30
- 26
Why is it a best practice to use both SAST and DAST in an application security program?
Select an answer first - 27
Which type of vulnerability is DAST more likely to detect than SAST?
Select an answer first - 28
A company is developing a customer-facing web application that will be subject to strict compliance requirements. The security team wants to ensure that the application is thoroughly tested before launch. They have a limited budget and must choose between investing in SAST, DAST, or a combination. The application has a complex authorization model and handles sensitive personal data. Which testing strategy provides the most comprehensive coverage within the budget?
Select an answer first - 29
A security team is designing a comprehensive application security testing program for a web application that is developed using agile methodology with frequent releases. They want to integrate security testing into the CI/CD pipeline. Which of the following practices should they implement? Select all that apply.
Select an answer first - 30
Which statement best describes Static Application Security Testing (SAST)?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DSE” is a trademark of its owner, used for identification only.