
EC-CouncilCertified DevSecOps Engineer
Domain 4Objective 1
Dynamic Application Security Testing (DAST) Concepts and Tools ECDE Practice Questions (Page 1)
Part of the Test Stage: DAST and CI/CD Security domain, which makes up ~9% of our current practice bank.
43questions here
9free pages
7concepts
Questions 1–5
- 1
What is the primary purpose of Dynamic Application Security Testing (DAST) in a CI/CD pipeline?
Select an answer first - 2
A development team is debating whether to use SAST or DAST for their CI/CD pipeline. They have a Node.js application with many third-party libraries and they want to identify vulnerabilities that are only exploitable at runtime, such as SQL injection and cross-site scripting. Which approach should they choose?
Select an answer first - 3
A DAST scan has identified a cross-site scripting (XSS) vulnerability in a web application. The development team is unsure how to reproduce the issue. What is the best way to help the developers understand and fix the vulnerability?
Select an answer first - 4
When DAST identifies a vulnerability in a CI/CD pipeline, what is the recommended first step for handling the result?
Select an answer first - 5
What is the best way to communicate a DAST finding to a developer who is not a security specialist?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECDE” is a trademark of its owner, used for identification only.