
EC-CouncilCertified DevSecOps Engineer
Domain 4Objective 1
Dynamic Application Security Testing (DAST) Concepts and Tools ECDE Practice Questions (Page 4)
Part of the Test Stage: DAST and CI/CD Security domain, which makes up ~9% of our current practice bank.
43questions here
9free pages
7concepts
Questions 16–20
- 16
How does DAST differ from SAST in terms of when it can be performed in the software development lifecycle?
Select an answer first - 17
A company is building a new REST API that uses OAuth2 for authentication and plans to deploy it on Kubernetes. The DevSecOps team needs to select a DAST tool that can be integrated into their GitLab CI pipeline and can authenticate to the API to scan authenticated endpoints. Which tool selection is most appropriate?
Select an answer first - 18
A team is evaluating testing tools for a microservices architecture where each service is developed independently and deployed frequently. They want to catch runtime vulnerabilities that depend on how services interact. Which testing approach is most suitable?
Select an answer first - 19
Which practice best supports a collaborative DevSecOps approach to DAST?
Select an answer first - 20
A security team runs DAST scans and generates reports with many findings. Developers complain that the reports are too technical and do not provide actionable steps. The team wants to improve the remediation workflow. What is the most effective approach?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECDE” is a trademark of its owner, used for identification only.