
EC-CouncilCertified DevSecOps Engineer
Domain 5Objective 3
Infrastructure as Code (IaC) Security ECDE Practice Questions (Page 8)
Part of the Release and Deploy Stage domain, which makes up ~14% of our current practice bank.
51questions here
11free pages
9concepts
Questions 36–40
- 36
A team manages their production environment with Terraform. A security audit reveals that a security group rule was manually added to an EC2 instance outside of Terraform, and a developer also changed the instance type through the AWS console. The team wants to detect and correct such unauthorized changes automatically. Which approach should be used?
Select an answer first - 37
A team uses Terraform to manage a Kubernetes cluster on AWS. They have a drift detection job that runs every hour and compares the Terraform state to the live cluster. The job frequently reports drift because the Kubernetes cluster autoscaler changes the desired capacity of node groups. The team wants to reduce false positives without losing visibility into real drift. What is the best approach?
Select an answer first - 38
A team uses Terraform to provision Azure resources. They need to pass a database password to a VM without exposing it in the Terraform state file. Which approach should they use?
Select an answer first - 39
A team uses Terraform to manage infrastructure and stores state in an S3 backend. They currently have secrets in the state file because they used a resource that generates a password. They want to eliminate secrets from the state file without breaking existing infrastructure. Which approach is the most secure and practical?
Select an answer first - 40
What is a key security best practice when using Ansible for infrastructure automation?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECDE” is a trademark of its owner, used for identification only.