Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified DevSecOps Engineer

Domain 6Objective 3

Compliance as Code ECDE Practice Questions (Page 3)

Part of the Operate and Monitor Stage domain, which makes up ~21% of our current practice bank.

50questions here
10free pages
8concepts

Questions 11–15

  1. 11expert · hard

    A company uses Terraform to deploy infrastructure to AWS and Azure. They want to enforce a policy that all resources have a 'cost-center' tag. The policy must be evaluated before any resource is created, and the team wants to use a single policy-as-code tool that works across both clouds. Which approach should they use?

    Select an answer first
  2. 12application · medium

    A DevSecOps engineer is configuring a CI/CD pipeline for a payment application that must meet PCI DSS. The compliance team wants to ensure that no container image containing a known critical vulnerability can be deployed to the production cluster. The engineer needs to add a check that runs after the image is built but before it is pushed to the registry. Which approach should the engineer take?

    Select an answer first
  3. 13expert · hard

    A DevSecOps team is integrating compliance checks into their CI/CD pipeline. They have a policy that blocks deployment if any critical vulnerability is found. However, a critical vulnerability is discovered in a third-party library that has no fix yet. The team needs to proceed with the release to meet a regulatory deadline. They want to maintain an audit trail and ensure that the exception is temporary and reviewed. What is the best approach?

    Select an answer first
  4. 14application · medium

    An organization must provide auditors with evidence that every infrastructure change was validated against internal security policies before being deployed. The team uses Terraform and a policy-as-code tool that runs during the CI/CD pipeline. What should the team implement to produce the required audit trail?

    Select an answer first
  5. 15application · medium

    A DevSecOps team is adopting compliance as code for a payment application. They want to enforce PCI DSS requirements (e.g., encryption in transit, no default credentials) as automated checks that run during CI. The team also needs to ensure that any change to a compliance policy is reviewed and can be rolled back if it produces false positives. Which approach best satisfies these requirements?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECDE” is a trademark of its owner, used for identification only.