
EC-CouncilCertified DevSecOps Engineer
Domain 6Objective 3
Compliance as Code ECDE Practice Questions (Page 2)
Part of the Operate and Monitor Stage domain, which makes up ~21% of our current practice bank.
50questions here
10free pages
8concepts
Questions 6–10
- 6
An organization must demonstrate to auditors that its CI/CD pipeline enforces a policy requiring all container images to be signed. The team uses a policy-as-code tool to check image signatures during the build stage. What should they produce to provide the required evidence?
Select an answer first - 7
A financial services company must demonstrate to auditors that their CI/CD pipeline enforces segregation of duties and that no code can be deployed without passing security and compliance checks. They need to generate a report that shows the pipeline history, who approved each stage, and the results of automated compliance checks. What is the most effective way to produce this audit evidence?
Select an answer first - 8
A company wants to implement continuous compliance monitoring for their AWS environment. They need to detect changes to security group rules, alert on non-compliant changes, and maintain a history of changes for auditing. Which AWS services or features should they use? Select all that apply.
Select an answer first - 9
A DevSecOps team maintains a set of compliance policies as code in a Git repository. They want to ensure that any change to a policy is reviewed by the security team and that the exact policy version used in a deployment can be traced. Which practice should they adopt?
Select an answer first - 10
Which of the following is a key characteristic of an effective audit trail for compliance?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECDE” is a trademark of its owner, used for identification only.