
EC-CouncilCertified DevSecOps Engineer
Domain 6Objective 3
Compliance as Code ECDE Practice Questions (Page 7)
Part of the Operate and Monitor Stage domain, which makes up ~21% of our current practice bank.
50questions here
10free pages
8concepts
Questions 31–35
- 31
An organization has deployed a web application on AWS. The security team wants to continuously monitor for compliance drift, such as security groups allowing SSH from 0.0.0.0/0 or S3 buckets becoming public. They also want to automatically remediate these issues and generate an audit trail of what was fixed. Which solution best meets these requirements?
Select an answer first - 32
A company must provide auditors with evidence that its CI/CD pipeline enforces a policy requiring all infrastructure changes to be reviewed and approved. The pipeline uses a policy-as-code tool that checks for an approval record in the change management system. The auditors want to see that the policy was actually enforced for each deployment. What is the best way to provide this evidence?
Select an answer first - 33
What is the primary benefit of integrating compliance checks as gates in the CI/CD pipeline?
Select an answer first - 34
A company uses Azure Policy to enforce tagging on all resources. They notice that some resources are created without required tags, and they want to automatically add the missing tags without manual intervention. They also need a record of when the remediation occurred for auditing. What should they configure?
Select an answer first - 35
Which of the following is an example of an automated compliance check that can be run during the deploy stage?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECDE” is a trademark of its owner, used for identification only.