
EC-CouncilCertified DevSecOps Engineer
Domain 5Objective 3
Infrastructure as Code (IaC) Security ECDE Practice Questions (Page 5)
Part of the Release and Deploy Stage domain, which makes up ~14% of our current practice bank.
51questions here
11free pages
9concepts
Questions 21–25
- 21
A large enterprise uses Terraform to manage infrastructure across multiple AWS accounts. The security team wants to enforce a policy that prohibits the creation of IAM users with console passwords and requires that all S3 buckets have versioning enabled. They also want to ensure that any violation is caught before the infrastructure is deployed, but they have a constraint: the policy must be maintainable by the security team without requiring changes to the Terraform code. Which approach best satisfies these requirements?
Select an answer first - 22
An organization uses Terraform to manage AWS infrastructure. The security team wants to enforce a policy that all S3 buckets must have encryption enabled and that no security group may allow inbound traffic on port 22 from anywhere. They want this policy to be automatically enforced whenever Terraform code is pushed to the repository. Which approach should be used?
Select an answer first - 23
A security engineer is evaluating IaC scanning tools for a multi-cloud environment (AWS and Azure). They need to scan Terraform configurations for misconfigurations and compliance violations, and integrate the results into a Jenkins pipeline. The team also wants to enforce custom policies that are not covered by the tool's default rules. Which tool and approach best meets these requirements?
Select an answer first - 24
Why is detecting configuration drift important for maintaining security posture?
Select an answer first - 25
What is the purpose of using static analysis tools to scan IaC templates?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECDE” is a trademark of its owner, used for identification only.