
EC-CouncilCertified DevSecOps Engineer
Domain 4Objective 2
Building a CI/CD Pipeline ECDE Practice Questions (Page 2)
Part of the Test Stage: DAST and CI/CD Security domain, which makes up ~9% of our current practice bank.
50questions here
10free pages
8concepts
Questions 6–10
- 6
A large enterprise is implementing a CI/CD pipeline that must comply with strict access control policies. The security team requires that no developer can modify the pipeline definition or access production credentials. The pipeline is hosted on a shared CI server. Which configuration should be implemented?
Select an answer first - 7
A company wants to ensure that every code change is integrated into the main branch at least once a day and that the application is always in a deployable state. They do not want to automate the deployment to production yet. Which practice should they adopt?
Select an answer first - 8
In a typical CI/CD pipeline, what is the correct order of the main stages?
Select an answer first - 9
A DevSecOps team has a pipeline that includes DAST. They notice that the DAST scan often fails due to false positives, causing the pipeline to be blocked. The team wants to reduce false positives without missing real vulnerabilities. Which strategy should they implement?
Select an answer first - 10
Why is it important to set up monitoring and feedback mechanisms in a CI/CD pipeline?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECDE” is a trademark of its owner, used for identification only.