Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified DevSecOps Engineer

Domain 4Objective 1

Dynamic Application Security Testing (DAST) Concepts and Tools ECDE Practice Questions (Page 5)

Part of the Test Stage: DAST and CI/CD Security domain, which makes up ~9% of our current practice bank.

43questions here
9free pages
7concepts

Questions 21–25

  1. 21foundation · easy

    Which of the following is a key limitation of DAST that a DevSecOps engineer should consider when integrating it into a CI/CD pipeline?

    Select an answer first
  2. 22application · medium

    A startup with a small budget needs to integrate DAST into its CI/CD pipeline. The team is comfortable with open-source tools and uses GitHub Actions. The application is a simple CRUD web app with basic authentication. Which DAST tool choice is most appropriate?

    Select an answer first
  3. 23foundation · easy

    When evaluating DAST tools for integration into a CI/CD pipeline, which capability is essential for automated security testing?

    Select an answer first
  4. 24application · medium

    A DAST scan of a web application is missing many pages because the application uses JavaScript to render content dynamically. The scanner only sees the initial HTML and does not execute JavaScript. What should the team configure to improve scan coverage?

    Select an answer first
  5. 25expert · hard

    A company is selecting a DAST tool for a microservices architecture with multiple services that communicate via REST APIs. The team wants to scan the entire application, but each service has its own authentication mechanism. They also need to integrate the tool into their CI/CD pipeline with minimal false positives. What is the most important consideration when selecting a DAST tool?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECDE” is a trademark of its owner, used for identification only.