Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified DevSecOps Engineer

Domain 5Objective 3

Infrastructure as Code (IaC) Security ECDE Practice Questions (Page 4)

Part of the Release and Deploy Stage domain, which makes up ~14% of our current practice bank.

51questions here
11free pages
9concepts

Questions 16–20

  1. 16application · medium

    A team uses Ansible to deploy applications. They need to pass API tokens to playbooks without exposing them in the repository or in the process list. Which method should they use?

    Select an answer first
  2. 17application · medium

    A security engineer wants to scan Terraform code for misconfigurations such as open security groups and unencrypted storage. The scans should run automatically on every commit and block the merge if critical issues are found. Which tool should be used?

    Select an answer first
  3. 18application · medium

    An organization wants to enforce that all AWS S3 buckets created via CloudFormation have encryption enabled and versioning turned on. They want to automate this enforcement in the CI/CD pipeline before deployment. Which tool and approach should they use?

    Select an answer first
  4. 19application · medium

    A developer accidentally commits a Terraform file that contains an AWS access key ID and secret access key. The security team needs to prevent this from happening again. Which combination of controls should be implemented?

    Select an answer first
  5. 20foundation · medium

    Why is it important to use environment variables for secrets in IaC rather than hardcoding them?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECDE” is a trademark of its owner, used for identification only.