
EC-CouncilCertified DevSecOps Engineer
Domain 3Objective 2
Integrating the Code Repo to SAST Tools ECDE Practice Questions (Page 2)
Part of the Code and Build Stage: SAST and Secure Code Review domain, which makes up ~15% of our current practice bank.
30questions here
6free pages
5concepts
Questions 6–10
- 6
A SAST tool is integrated with a GitHub repository via webhook. The security team wants to ensure that developers are notified of new findings and that the findings are tracked until they are fixed. Which feedback-loop mechanism should the team configure?
Select an answer first - 7
To ensure that every code change is scanned, a SAST tool should be configured to trigger on which repository event?
Select an answer first - 8
After integrating a SAST tool with Azure DevOps, the security team wants scan findings to appear as comments on the pull request that introduced the vulnerability, so developers can fix issues before merging. Which configuration should be used to achieve this feedback loop?
Select an answer first - 9
A SAST tool is being configured to scan a Git repository that contains both source code and large binary files. The team wants to scan only the source code and avoid scanning the binaries to save time. The SAST tool supports path filters and file-type filters. The team also wants to ensure that the SAST tool's credentials are not exposed to developers. Which configuration should the team use?
Select an answer first - 10
When configuring a SAST tool to connect to a private code repository, which of the following is typically required to authenticate the SAST tool?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECDE” is a trademark of its owner, used for identification only.