
EC-CouncilCertified DevSecOps Engineer
Domain 1Objective 3
Integrating Security into DevOps and the Shift-Left Approach ECDE Practice Questions (Page 7)
Part of the DevOps and DevSecOps Foundations domain, which makes up ~22% of our current practice bank.
56questions here
12free pages
8concepts
Questions 31–35
- 31
A DevSecOps team wants to detect security issues that only appear under production load, such as race conditions or resource exhaustion. They already run SAST and DAST in staging. What should they add to improve detection?
Select an answer first - 32
A platform team wants to enforce consistent security policies across multiple microservices. They plan to define security controls as code and integrate them into the CI/CD pipeline. Which approach best exemplifies security as code?
Select an answer first - 33
Which of the following is a key benefit of shifting security left in the DevOps lifecycle?
Select an answer first - 34
A large enterprise is adopting shift-left security. The security team wants to enforce a comprehensive set of security gates, but developers are resisting because the pipeline has become slow and they feel the security team is imposing rules without understanding the development context. The team wants to balance security with developer productivity. Which approach best addresses this challenge?
Select an answer first - 35
A team is deploying a critical application and wants to ensure that security is integrated from planning through operations. They have already added SAST and DAST to the pipeline. What additional practice should they implement to cover the operations phase?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECDE” is a trademark of its owner, used for identification only.