
EC-CouncilCertified DevSecOps Engineer
Domain 4Objective 1
Dynamic Application Security Testing (DAST) Concepts and Tools ECDE Practice Questions (Page 8)
Part of the Test Stage: DAST and CI/CD Security domain, which makes up ~9% of our current practice bank.
43questions here
9free pages
7concepts
Questions 36–40
- 36
A DevSecOps team is integrating DAST into a CI/CD pipeline that deploys to a Kubernetes cluster. They need to scan the application before it is exposed to the internet. The team has limited resources and cannot maintain a separate staging environment. What is the most efficient approach to run DAST in this pipeline?
Select an answer first - 37
A DevSecOps team is integrating DAST into their CI/CD pipeline for a Java Spring Boot application that uses OAuth2 for authentication. The team wants to run DAST scans on every pull request before merge. However, the application requires a valid OAuth2 token to access most endpoints. What is the most effective approach to configure the DAST tool for this scenario?
Select an answer first - 38
After a DAST scan, the security team finds a critical vulnerability in a legacy application that is scheduled for decommissioning in six months. The development team is busy with a new feature. What should the security team do?
Select an answer first - 39
After running a DAST scan in the CI pipeline, the security team receives a report with 150 findings. The development team is overwhelmed and unsure which issues to fix first. The security team wants to prioritize remediation effectively. What is the best first step?
Select an answer first - 40
What is the purpose of defining a scan scope in a DAST tool?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECDE” is a trademark of its owner, used for identification only.