
EC-CouncilCertified DevSecOps Engineer
Domain 4Objective 2
Building a CI/CD Pipeline ECDE Practice Questions (Page 4)
Part of the Test Stage: DAST and CI/CD Security domain, which makes up ~9% of our current practice bank.
50questions here
10free pages
8concepts
Questions 16–20
- 16
A DevSecOps engineer is configuring a CI/CD pipeline for a Python application. The pipeline needs to install dependencies, run tests, and deploy to a cloud environment. The team wants to ensure that the pipeline does not have write access to the production environment except during the deployment stage. What is the best way to achieve this?
Select an answer first - 17
What is the primary purpose of integrating DAST into a CI/CD pipeline?
Select an answer first - 18
A company is implementing a CI/CD pipeline for a mobile application. The pipeline must build the app, run unit tests, and then run DAST against the backend API that the app uses. The team wants to ensure that the backend is deployed before DAST runs. What is the correct pipeline stage order?
Select an answer first - 19
A DevSecOps team is building a pipeline for a web application that must be deployed to multiple regions. The pipeline currently builds and tests the application, then deploys to one region. The team wants to deploy to other regions only if the first deployment is successful and passes a DAST scan. What is the best pipeline design?
Select an answer first - 20
A team uses a CI/CD pipeline that pulls source code from a Git repository and builds a Docker image. The pipeline needs to push the image to a private container registry. The team wants to avoid storing the registry password in the pipeline configuration file. What is the best approach?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECDE” is a trademark of its owner, used for identification only.