
EC-CouncilCertified DevSecOps Engineer
Domain 6Objective 3
Compliance as Code ECDE Practice Questions (Page 5)
Part of the Operate and Monitor Stage domain, which makes up ~21% of our current practice bank.
50questions here
10free pages
8concepts
Questions 21–25
- 21
What is the primary purpose of continuous compliance monitoring in a deployed environment?
Select an answer first - 22
A team manages compliance policies for multiple applications in a monorepo. They need to ensure that a change to a policy does not break other applications' pipelines. They also need to know which version of a policy was used for a specific build. What should they implement?
Select an answer first - 23
Which practice is essential for managing compliance policies as code?
Select an answer first - 24
A company is adopting HashiCorp Sentinel to enforce that all Terraform plans for AWS resources include appropriate tags. The DevSecOps team wants to run this check automatically whenever a developer opens a pull request that changes Terraform code. Which approach should they use?
Select an answer first - 25
An organization uses Azure Policy to enforce that all VMs have the 'Managed Disks' property enabled. They have enabled automatic remediation for the policy. However, they notice that some VMs are repeatedly marked non-compliant even after remediation runs. The remediation task appears to succeed, but the VM becomes non-compliant again within a few hours. What is the most likely cause and what should the team do?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECDE” is a trademark of its owner, used for identification only.