
EC-CouncilCertified DevSecOps Engineer
Domain 1Objective 3
Integrating Security into DevOps and the Shift-Left Approach ECDE Practice Questions (Page 9)
Part of the DevOps and DevSecOps Foundations domain, which makes up ~22% of our current practice bank.
56questions here
12free pages
8concepts
Questions 41–45
- 41
A DevSecOps team has implemented continuous monitoring in production. They receive a high volume of security alerts, many of which are false positives. The team is becoming desensitized to alerts and may miss real incidents. Which strategy best improves the effectiveness of the monitoring feedback loop?
Select an answer first - 42
A team is building a REST API and wants to automatically test for common web vulnerabilities such as SQL injection and cross-site scripting. They want to run this test against a deployed instance in a staging environment. Which type of automated security testing should they integrate into the pipeline?
Select an answer first - 43
An organization wants to enforce consistent security policies across multiple CI/CD pipelines. Currently, each pipeline has manually configured security steps that often drift. Which practice best addresses this using security as code?
Select an answer first - 44
A team is building a microservices application with a CI/CD pipeline. They want to integrate security into the pipeline without duplicating security checks across many service pipelines. They also need to ensure that security policies are versioned and auditable. Which approach best meets these requirements?
Select an answer first - 45
A DevSecOps team has deployed an application and wants to detect security issues in real time and automatically trigger a response. Which combination of practices best enables continuous security monitoring and feedback?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECDE” is a trademark of its owner, used for identification only.