Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified DevSecOps Engineer

Domain 5Objective 3

Infrastructure as Code (IaC) Security ECDE Practice Questions (Page 9)

Part of the Release and Deploy Stage domain, which makes up ~14% of our current practice bank.

51questions here
11free pages
9concepts

Questions 41–45

  1. 41application · medium

    A team stores database credentials in a Terraform variables file that is committed to the repository. They want to move to a secure approach without exposing secrets in the codebase. Which solution should they adopt?

    Select an answer first
  2. 42foundation · medium

    Which of the following is an example of a policy-as-code framework?

    Select an answer first
  3. 43expert · hard

    A large enterprise uses Terraform Cloud for remote state and runs. They want to enforce that all workspaces use a specific version of Terraform and that no workspace can create resources outside of a defined set of AWS regions. They also want to prevent developers from bypassing the policy by using the API directly. Which approach should they take?

    Select an answer first
  4. 44foundation · medium

    What is the recommended way to handle secrets (e.g., API keys, passwords) in IaC code?

    Select an answer first
  5. 45application · medium

    A developer writes a CloudFormation template that creates an IAM role with a policy that allows 's3:*' on all resources. The security team wants to enforce least privilege. What is the best way to catch this before deployment?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECDE” is a trademark of its owner, used for identification only.