Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified DevSecOps Engineer

Domain 4Objective 1

Dynamic Application Security Testing (DAST) Concepts and Tools ECDE Practice Questions (Page 1)

Part of the Test Stage: DAST and CI/CD Security domain, which makes up ~9% of our current practice bank.

43questions here
9free pages
7concepts

Questions 1–5

  1. 1foundation · easy

    What is the primary purpose of Dynamic Application Security Testing (DAST) in a CI/CD pipeline?

    Select an answer first
  2. 2application · medium

    A development team is debating whether to use SAST or DAST for their CI/CD pipeline. They have a Node.js application with many third-party libraries and they want to identify vulnerabilities that are only exploitable at runtime, such as SQL injection and cross-site scripting. Which approach should they choose?

    Select an answer first
  3. 3application · medium

    A DAST scan has identified a cross-site scripting (XSS) vulnerability in a web application. The development team is unsure how to reproduce the issue. What is the best way to help the developers understand and fix the vulnerability?

    Select an answer first
  4. 4foundation · easy

    When DAST identifies a vulnerability in a CI/CD pipeline, what is the recommended first step for handling the result?

    Select an answer first
  5. 5foundation · easy

    What is the best way to communicate a DAST finding to a developer who is not a security specialist?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECDE” is a trademark of its owner, used for identification only.