
EC-CouncilCertified DevSecOps Engineer
Domain 1Objective 3
Integrating Security into DevOps and the Shift-Left Approach ECDE Practice Questions (Page 10)
Part of the DevOps and DevSecOps Foundations domain, which makes up ~22% of our current practice bank.
56questions here
12free pages
8concepts
Questions 46–50
- 46
A security team currently reviews code only after the development team finishes a feature. Developers complain that security reviews are a bottleneck and that they receive feedback too late. The organization wants to embed security into the DevOps culture. Which change best addresses the cultural and collaboration challenge?
Select an answer first - 47
Which of the following is a common challenge when implementing shift-left security?
Select an answer first - 48
A development team is adopting a DevSecOps approach. They currently run a nightly SAST scan after the code is merged into the main branch, and developers often receive vulnerability reports days after they wrote the code. The team wants to reduce the time between code commit and vulnerability discovery. Which change best aligns with the shift-left security principle?
Select an answer first - 49
A development team is building a Node.js application with many third-party dependencies. They want to automatically detect known vulnerabilities in those dependencies before they reach production. Which automated security testing tool should they integrate into the CI pipeline?
Select an answer first - 50
What cultural change is essential for successfully embedding security into DevOps?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECDE” is a trademark of its owner, used for identification only.