
EC-CouncilCertified DevSecOps Engineer
Domain 5Objective 3
Infrastructure as Code (IaC) Security ECDE Practice Questions (Page 9)
Part of the Release and Deploy Stage domain, which makes up ~14% of our current practice bank.
51questions here
11free pages
9concepts
Questions 41–45
- 41
A team stores database credentials in a Terraform variables file that is committed to the repository. They want to move to a secure approach without exposing secrets in the codebase. Which solution should they adopt?
Select an answer first - 42
Which of the following is an example of a policy-as-code framework?
Select an answer first - 43
A large enterprise uses Terraform Cloud for remote state and runs. They want to enforce that all workspaces use a specific version of Terraform and that no workspace can create resources outside of a defined set of AWS regions. They also want to prevent developers from bypassing the policy by using the API directly. Which approach should they take?
Select an answer first - 44
What is the recommended way to handle secrets (e.g., API keys, passwords) in IaC code?
Select an answer first - 45
A developer writes a CloudFormation template that creates an IAM role with a policy that allows 's3:*' on all resources. The security team wants to enforce least privilege. What is the best way to catch this before deployment?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECDE” is a trademark of its owner, used for identification only.