Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified DevSecOps Engineer

Domain 6Objective 1

Container Security Concepts and Best Practices ECDE Practice Questions (Page 1)

Part of the Operate and Monitor Stage domain, which makes up ~21% of our current practice bank.

40questions here
8free pages
8concepts

Questions 1–5

  1. 1foundation · easy

    Which Kubernetes resource is designed to securely store sensitive data such as passwords and API keys?

    Select an answer first
  2. 2expert · hard

    A multi-tenant Kubernetes cluster hosts applications from different business units. The security team must ensure that a compromised pod in one namespace cannot reach pods in another namespace, but they also need to allow the monitoring team's pod to access metrics from all namespaces. Which approach best balances security and operational needs?

    Select an answer first
  3. 3foundation · easy

    Which practice is most effective for minimizing a container image's attack surface?

    Select an answer first
  4. 4application · medium

    An organization uses a managed Kubernetes service and stores sensitive configuration data, such as database credentials, in Kubernetes Secrets. The security team is concerned about unauthorized access to these secrets and wants to ensure that only specific service accounts can read them, while also maintaining an audit trail of access. What should they implement?

    Select an answer first
  5. 5application · medium

    A security operations team wants to detect anomalous behavior in their containerized environment, such as a container spawning a shell or making unexpected network connections. They need a solution that provides real-time visibility into container activity and can trigger alerts. What should they implement?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECDE” is a trademark of its owner, used for identification only.