
EC-CouncilCertified DevSecOps Engineer
Domain 4Objective 1
Dynamic Application Security Testing (DAST) Concepts and Tools ECDE Practice Questions (Page 2)
Part of the Test Stage: DAST and CI/CD Security domain, which makes up ~9% of our current practice bank.
43questions here
9free pages
7concepts
Questions 6–10
- 6
A team is considering adding DAST to their CI/CD pipeline. They currently use SAST and dependency scanning. They want to identify vulnerabilities that are only visible when the application is running, such as misconfigurations and business logic flaws. What is the best reason to add DAST?
Select an answer first - 7
A company has a DevSecOps culture where developers are responsible for fixing security findings. However, the security team notices that developers often close DAST findings as 'false positive' without proper investigation. What should the security team do to ensure findings are properly addressed?
Select an answer first - 8
A team is comparing DAST and IAST for their CI/CD pipeline. They want to identify vulnerabilities in their Java application during automated tests. The application is complex and has many internal components. Which approach would provide the most comprehensive coverage during the test stage?
Select an answer first - 9
A DAST scan of a web application is producing many false positives for a form that uses a CAPTCHA. The scanner cannot submit the form because it cannot solve the CAPTCHA. What should the team do to improve scan accuracy?
Select an answer first - 10
When analyzing a DAST report, which factor should be used to prioritize which vulnerability to fix first?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECDE” is a trademark of its owner, used for identification only.