
EC-CouncilCertified DevSecOps Engineer
Domain 6Objective 1
Container Security Concepts and Best Practices ECDE Practice Questions (Page 4)
Part of the Operate and Monitor Stage domain, which makes up ~21% of our current practice bank.
40questions here
8free pages
8concepts
Questions 16–20
- 16
What is the primary purpose of signing a container image?
Select an answer first - 17
An organization runs a Kubernetes cluster with multiple teams. The security team wants to ensure that each team can only access resources in their own namespace and that any unauthorized access attempts are logged. What should they implement?
Select an answer first - 18
What is the primary purpose of centralized logging in a container environment?
Select an answer first - 19
A development team frequently pushes new builds of a Node.js application to a private registry. A security review found that several images contain outdated OS packages and that developers sometimes overwrite tags like 'latest'. The team wants to ensure that only verified, up-to-date images are deployed to production. Which combination of practices should be enforced?
Select an answer first - 20
A security operations team is investigating a potential container escape. They need to determine whether a process in a container accessed a host file. The container has already been terminated, and the team has access to the host's audit logs and the container's previous logs. Which data source would provide the most reliable evidence?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECDE” is a trademark of its owner, used for identification only.