
EC-CouncilCertified DevSecOps Engineer
Domain 6Objective 1
Container Security Concepts and Best Practices ECDE Practice Questions (Page 6)
Part of the Operate and Monitor Stage domain, which makes up ~21% of our current practice bank.
40questions here
8free pages
8concepts
Questions 26–30
- 26
A development team builds a Python application image. The Dockerfile uses 'python:latest' as the base image and installs packages with pip without version pinning. The security team wants to reduce the risk of supply chain attacks. Which change should be made?
Select an answer first - 27
What is the primary purpose of a Kubernetes NetworkPolicy?
Select an answer first - 28
Which characteristic of containerized environments introduces a unique security challenge compared to traditional virtual machines?
Select an answer first - 29
A company uses a public container registry to store images. A security audit found that some images were pulled from a public repository that was later compromised. The company wants to prevent the use of untrusted images in their CI/CD pipeline. Which measure should be implemented?
Select an answer first - 30
A Kubernetes cluster hosts multiple applications from different teams. The security team wants to ensure that a developer from Team A cannot access secrets belonging to Team B, and that pods from Team A cannot read Team B's secrets. Which set of controls should be implemented?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECDE” is a trademark of its owner, used for identification only.