
EC-CouncilCertified DevSecOps Engineer
Domain 4Objective 2
Building a CI/CD Pipeline ECDE Practice Questions (Page 6)
Part of the Test Stage: DAST and CI/CD Security domain, which makes up ~9% of our current practice bank.
50questions here
10free pages
8concepts
Questions 26–30
- 26
A product team wants to release new features frequently but also wants to ensure that security vulnerabilities are caught before production. They are considering whether to use continuous delivery or continuous deployment. The pipeline currently runs DAST in staging. The team wants to have a human review security reports before production releases. What is the best approach?
Select an answer first - 27
A DevSecOps team is integrating DAST into a pipeline for a web application that uses a third-party payment gateway. The DAST scanner must not send malicious payloads to the payment gateway. The team wants to run DAST automatically in staging. What is the best way to handle this constraint?
Select an answer first - 28
What is a recommended access control practice for CI/CD pipeline execution?
Select an answer first - 29
A company wants to integrate DAST into their CI/CD pipeline but is concerned about the time it takes to run a full scan. They want to provide fast feedback to developers without waiting for the entire scan. Which approach should they take?
Select an answer first - 30
A DevSecOps team has integrated DAST into their pipeline. The DAST scan runs on every merge to the main branch and takes 30 minutes. The team wants to monitor the pipeline's performance and be alerted if the DAST stage exceeds 45 minutes. What should be configured?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECDE” is a trademark of its owner, used for identification only.