
EC-CouncilCertified DevSecOps Engineer
Domain 4Objective 2
Building a CI/CD Pipeline ECDE Practice Questions (Page 3)
Part of the Test Stage: DAST and CI/CD Security domain, which makes up ~9% of our current practice bank.
50questions here
10free pages
8concepts
Questions 11–15
- 11
A company has a CI/CD pipeline that deploys a web application to a staging environment. They want to integrate DAST but are concerned about the scan interfering with the staging environment's performance and causing false positives. The staging environment is shared with other teams. Which approach should they take?
Select an answer first - 12
A DevSecOps team has integrated DAST into their CI/CD pipeline. They want to monitor the pipeline's performance and security results over time. Which set of metrics should they track to gain the most useful feedback?
Select an answer first - 13
Which of the following is an example of a feedback mechanism in a CI/CD pipeline?
Select an answer first - 14
A DevSecOps team is designing a pipeline for a large monorepo with multiple independent services. The pipeline must build and test only the services that changed, but still run DAST against the entire staging environment. The team wants to minimize pipeline time while maintaining security coverage. What is the best approach?
Select an answer first - 15
Which of the following is a security best practice for managing secrets (e.g., API keys, passwords) in a CI/CD pipeline?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECDE” is a trademark of its owner, used for identification only.