
EC-CouncilCertified DevSecOps Engineer
Domain 6Objective 3
Compliance as Code ECDE Practice Questions (Page 9)
Part of the Operate and Monitor Stage domain, which makes up ~21% of our current practice bank.
50questions here
10free pages
8concepts
Questions 41–45
- 41
During the build stage of a CI/CD pipeline, which action best represents automated compliance validation of infrastructure code?
Select an answer first - 42
A company uses AWS Config to monitor its AWS account for compliance with the CIS AWS Foundations Benchmark. They have enabled the appropriate AWS Config rules and receive daily compliance reports. Recently, a developer manually modified a security group to open port 22 to the world, and the change was detected by AWS Config. The company's security policy requires that such changes be automatically reverted. However, the security group is also used by a legacy application that occasionally requires temporary SSH access, and the developer's change was intentional for a maintenance window. What is the best approach to balance automated remediation with the legitimate need for temporary changes?
Select an answer first - 43
A company is adopting compliance as code for the first time. They have a mix of legacy infrastructure that is manually configured and new infrastructure that is deployed via Terraform. The compliance team wants to enforce a policy that all servers must have a specific security agent installed. The policy must be enforced for both legacy and new servers. What is the best approach?
Select an answer first - 44
An organization uses AWS Config to monitor EC2 instances for compliance with a rule that requires instances to have specific tags. When a new instance is launched without the required tags, AWS Config marks it non-compliant. The team wants to automatically add the missing tags. What should they implement?
Select an answer first - 45
A company uses Open Policy Agent (OPA) to enforce that all AWS S3 buckets have encryption enabled. The policy is stored in a Git repository and is used by the CI/CD pipeline to validate infrastructure-as-code templates. After a recent change to the policy, several legitimate deployments were blocked because the policy incorrectly required encryption for temporary build buckets. The team needs to quickly revert to the previous behavior while they fix the policy. What should they do?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECDE” is a trademark of its owner, used for identification only.