
EC-CouncilCertified DevSecOps Engineer
Domain 6Objective 3
Compliance as Code ECDE Practice Questions (Page 10)
Part of the Operate and Monitor Stage domain, which makes up ~21% of our current practice bank.
50questions here
10free pages
8concepts
Questions 46–50
- 46
What is the primary role of policy-as-code frameworks like Open Policy Agent (OPA) and HashiCorp Sentinel in a DevSecOps pipeline?
Select an answer first - 47
Which tool is specifically designed as a policy-as-code framework that uses a high-level declarative language to define policies for cloud-native environments?
Select an answer first - 48
A DevSecOps team wants to ensure that no container image is deployed to production unless it has passed a vulnerability scan and a license compliance check. They also want to be able to quickly disable a faulty compliance check without rewriting the pipeline. How should they implement this?
Select an answer first - 49
A company uses Azure Policy to enforce that all storage accounts have the 'Secure transfer required' setting enabled. They want to automatically fix any storage account that becomes non-compliant. What should they configure?
Select an answer first - 50
A DevSecOps team has deployed a web application on Azure and uses Azure Policy to enforce that all managed disks use encryption at rest. The team wants to detect when a resource becomes non-compliant after deployment and automatically restore compliance without manual intervention. Which combination of actions should they implement?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to ECDE
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECDE” is a trademark of its owner, used for identification only.