
EC-CouncilCertified DevSecOps Engineer
Domain 5Objective 3
Infrastructure as Code (IaC) Security ECDE Practice Questions (Page 6)
Part of the Release and Deploy Stage domain, which makes up ~14% of our current practice bank.
51questions here
11free pages
9concepts
Questions 26–30
- 26
A team uses Ansible to configure servers. They want to ensure that playbooks do not contain hardcoded passwords and that the playbooks are validated for syntax and security before deployment. Which combination of practices should they adopt?
Select an answer first - 27
Which of the following is a security check that can be performed in an IaC pipeline?
Select an answer first - 28
A company runs a production environment using Terraform. They have a mix of resources that are managed by Terraform and some that were created manually. A recent audit found that a manually created security group is allowing SSH from the internet, and a Terraform-managed EC2 instance was modified in the console. The team wants to detect and remediate drift, but they must avoid disrupting the manually created resources. Which approach should they take?
Select an answer first - 29
A startup is adopting IaC for the first time. They want to ensure that security is integrated into the deployment pipeline from the start. Which practice best aligns with the security implications of IaC in the release and deploy stage?
Select an answer first - 30
A company runs a web application on EC2 instances that are managed by Ansible. After a security incident, they want to reduce the attack surface by ensuring that instances are not manually modified over time. Which strategy best aligns with the concept of immutable infrastructure?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECDE” is a trademark of its owner, used for identification only.