
EC-CouncilCertified DevSecOps Engineer
Domain 1Objective 5
DevSecOps Pipeline, Strategy, and Tools ECDE Practice Questions (Page 3)
Part of the DevOps and DevSecOps Foundations domain, which makes up ~22% of our current practice bank.
40questions here
8free pages
7concepts
Questions 11–15
- 11
A DevSecOps team is building a pipeline for a microservices application. They want to ensure that container images are scanned for vulnerabilities before they are pushed to the production registry. They also want to enforce that only images that pass the scan can be deployed. Which approach best achieves this goal?
Select an answer first - 12
A healthcare organization is implementing a DevSecOps pipeline for a patient-facing application. The compliance team requires that all code changes be traceable to a ticket, that no production deployment occurs without an approved security review, and that audit logs be retained for seven years. The engineering team wants to deploy multiple times per day. The current manual security review takes two days. Which strategy best balances the compliance requirements with the engineering team's velocity?
Select an answer first - 13
A DevSecOps team has implemented a pipeline with SAST, DAST, and dependency scanning. The security team wants to measure the effectiveness of the pipeline. They have proposed the following metrics: (1) number of vulnerabilities found in production, (2) time to remediate a vulnerability, (3) number of builds that fail due to security checks, and (4) percentage of code coverage by SAST. Which combination of metrics best measures the effectiveness of the security controls in the pipeline?
Select an answer first - 14
A team is implementing a DevSecOps pipeline. They want to ensure that security checks are run consistently on every build. They are considering using a pipeline orchestration tool. What is the primary benefit of using an orchestration tool for this purpose?
Select an answer first - 15
A DevSecOps team is selecting a tool for dependency scanning. They have two options: Tool A is a commercial tool that integrates with their CI/CD platform and provides a centralized dashboard. Tool B is an open-source tool that can be run as a command-line utility. The team has a small budget but a strong preference for automation and centralized reporting. Which tool should they choose?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECDE” is a trademark of its owner, used for identification only.