
EC-CouncilCertified DevSecOps Engineer
Domain 3Objective 2
Integrating the Code Repo to SAST Tools ECDE Practice Questions (Page 1)
Part of the Code and Build Stage: SAST and Secure Code Review domain, which makes up ~15% of our current practice bank.
30questions here
6free pages
5concepts
Questions 1–5
- 1
After integrating a SAST tool with a GitHub repository, the security team wants developers to see scan results directly in their pull requests and be able to assign remediation tasks to specific team members. Which feature should the team enable in the SAST tool or its integration?
Select an answer first - 2
A team wants to integrate a SAST tool with a repository hosted on an on-premises Git server that does not support webhooks. The team needs scans to run automatically after every push and findings to be posted as comments on the corresponding commit. What is the most effective integration approach?
Select an answer first - 3
A team uses GitLab and wants SAST scans to run when a merge request is created, but not on every push to the source branch. The SAST tool integrates via webhook. Which webhook event should the team subscribe to?
Select an answer first - 4
A SAST tool needs to access a repository hosted on an internal Git server. The security team requires that the SAST tool's credentials be scoped to read-only access and that the connection be encrypted. The Git server supports SSH keys and HTTPS with personal access tokens. Which configuration should be used?
Select an answer first - 5
A company uses a SAST tool that only supports API-based integration. The team wants to trigger scans on every push to the 'main' branch in GitHub. The team also wants to ensure that the API call is authenticated securely and that the SAST tool's credentials are not exposed to developers. What should the team do?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECDE” is a trademark of its owner, used for identification only.