
EC-CouncilCertified DevSecOps Engineer
Domain 1Objective 5
DevSecOps Pipeline, Strategy, and Tools ECDE Practice Questions (Page 6)
Part of the DevOps and DevSecOps Foundations domain, which makes up ~22% of our current practice bank.
40questions here
8free pages
7concepts
Questions 26–30
- 26
Which approach best balances speed, security, and compliance when developing a DevSecOps pipeline strategy?
Select an answer first - 27
Which security testing type is BEST suited for integration into the early stages of a CI/CD pipeline?
Select an answer first - 28
A large enterprise is planning to implement a DevSecOps pipeline across multiple development teams. Each team uses a different CI/CD tool (Jenkins, GitLab CI, and GitHub Actions). The security team wants a unified view of security findings across all pipelines. They are considering: (1) standardizing on a single CI/CD tool, (2) using a centralized security orchestration platform, or (3) having each team report findings to a common dashboard. Which approach is most effective in achieving a unified view while minimizing disruption to the teams?
Select an answer first - 29
When evaluating a security tool for a pipeline, which feature directly supports automation?
Select an answer first - 30
A development team uses a CI/CD pipeline that builds and deploys a web application. They want to integrate DAST scanning into the pipeline. The DAST scan requires the application to be running in a test environment. What is the best way to integrate DAST into the pipeline?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECDE” is a trademark of its owner, used for identification only.