
EC-CouncilCertified DevSecOps Engineer
Domain 1Objective 3
Integrating Security into DevOps and the Shift-Left Approach ECDE Practice Questions (Page 3)
Part of the DevOps and DevSecOps Foundations domain, which makes up ~22% of our current practice bank.
56questions here
12free pages
8concepts
Questions 11–15
- 11
A team is building a CI/CD pipeline for a web application. They want to catch common coding flaws early, but they also need to verify that the running application does not expose sensitive data through its HTTP responses. Which combination of automated tests should be added to the pipeline?
Select an answer first - 12
In which DevOps phase would threat modeling typically be performed as a security practice?
Select an answer first - 13
Which best practice helps overcome the challenge of developers lacking security expertise in a shift-left approach?
Select an answer first - 14
A company is deciding between two security testing strategies: (1) running SAST on every commit and DAST on every release candidate, or (2) running only DAST on production after deployment. The company has a tight release schedule and limited security tooling budget. Which consideration is most important when choosing the shift-left strategy?
Select an answer first - 15
What is the core principle of shift-left security in a DevSecOps context?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECDE” is a trademark of its owner, used for identification only.