
EC-CouncilCertified DevSecOps Engineer
Domain 5Objective 3
Infrastructure as Code (IaC) Security ECDE Practice Questions (Page 3)
Part of the Release and Deploy Stage domain, which makes up ~14% of our current practice bank.
51questions here
11free pages
9concepts
Questions 11–15
- 11
A developer commits a Terraform configuration that includes an AWS IAM policy allowing `s3:*` on all resources. The security team wants to prevent this type of overly permissive policy from being deployed. Which control should be implemented in the CI pipeline?
Select an answer first - 12
What is the primary risk associated with an overly permissive IAM policy defined in an IaC template?
Select an answer first - 13
What is configuration drift in the context of IaC-managed environments?
Select an answer first - 14
Why should security checks be integrated into the CI/CD pipeline for IaC deployments?
Select an answer first - 15
A company wants to integrate security checks into their CI/CD pipeline for Terraform deployments. They need to ensure that every pull request is scanned for misconfigurations and that any policy violations block the merge. Which pipeline configuration best achieves this?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECDE” is a trademark of its owner, used for identification only.