
EC-CouncilCertified DevSecOps Engineer
Domain 4Objective 2
Building a CI/CD Pipeline ECDE Practice Questions (Page 9)
Part of the Test Stage: DAST and CI/CD Security domain, which makes up ~9% of our current practice bank.
50questions here
10free pages
8concepts
Questions 41–45
- 41
A team has a CI/CD pipeline that runs DAST on every merge to main. The DAST scan sometimes fails due to false positives, causing developers to ignore the results. The team wants to reduce false positives while maintaining security coverage. What is the best approach?
Select an answer first - 42
A DevSecOps team wants to set up monitoring for their CI/CD pipeline to alert on security scan failures and pipeline performance degradation. Which combination of tools and practices should they implement?
Select an answer first - 43
How do the build and test stages of a CI/CD pipeline typically interconnect?
Select an answer first - 44
A company is implementing a CI/CD pipeline for a financial application. The pipeline must comply with an audit requirement that all changes to production be traceable to a specific commit and an authorized user. The team uses a shared CI/CD service account for deployments. What is the best way to meet the audit requirement?
Select an answer first - 45
A company is setting up a CI/CD pipeline for a .NET application. They have a version control system, a build server, and a deployment target. The team wants to ensure that only artifacts that have passed all tests are deployed. What is the best practice?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECDE” is a trademark of its owner, used for identification only.