Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified DevSecOps Engineer

Domain 1Objective 5

DevSecOps Pipeline, Strategy, and Tools ECDE Practice Questions (Page 8)

Part of the DevOps and DevSecOps Foundations domain, which makes up ~22% of our current practice bank.

40questions here
8free pages
7concepts

Questions 36–40

  1. 36expert · hard

    A company is implementing a DevSecOps pipeline for a legacy application that is critical to business operations. The application has a large amount of technical debt and many known vulnerabilities. The team has limited resources and cannot fix all vulnerabilities immediately. What is the most effective strategy for managing this situation?

    Select an answer first
  2. 37expert · hard

    A DevSecOps team is tracking metrics for their pipeline. They have noticed that the 'time to remediate' metric is high, but the 'number of vulnerabilities in production' is low. Which of the following is the most likely explanation for this situation?

    Select an answer first
  3. 38application · medium

    A company's DevSecOps pipeline uses secrets (API keys, passwords) stored in environment variables in the CI system. The security team wants to ensure that secrets are not exposed in build logs. Which control should be implemented?

    Select an answer first
  4. 39application · medium

    A company's DevSecOps pipeline uses a shared Jenkins server that also runs builds for other teams. The security team is concerned that a compromised build could affect the pipeline's integrity. Which control should be implemented to secure the pipeline itself?

    Select an answer first
  5. 40application · medium

    A software company uses Jenkins for CI/CD and has a mix of Java and Node.js applications. The security team wants to add SAST scanning to the pipeline. They are evaluating two tools: Tool X is a commercial SAST tool with a Jenkins plugin, supports both Java and Node.js, and requires a license per developer. Tool Y is an open-source SAST tool that also supports both languages and has a command-line interface but no native Jenkins plugin. The team has a limited budget and wants to minimize custom scripting. Which tool should they select?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to ECDE

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECDE” is a trademark of its owner, used for identification only.