Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified DevSecOps Engineer

Domain 3Objective 2

Integrating the Code Repo to SAST Tools ECDE Practice Questions (Page 3)

Part of the Code and Build Stage: SAST and Secure Code Review domain, which makes up ~15% of our current practice bank.

30questions here
6free pages
5concepts

Questions 11–15

  1. 11foundation · easy

    What is the primary purpose of assigning remediation tasks to developers based on SAST scan results?

    Select an answer first
  2. 12application · medium

    A SAST tool is being configured to scan a monorepo that contains multiple projects. The team wants to scan only the 'backend' directory and exclude the 'legacy' directory. The SAST tool supports path filters during repository configuration. What should the team configure to achieve this?

    Select an answer first
  3. 13expert · hard

    A SAST tool posts scan results as comments on GitHub pull requests. The team notices that the same vulnerability is being reported on every commit to the PR, creating a long list of duplicate comments. The team wants to reduce noise while still ensuring that the developer sees the finding. What should the team configure?

    Select an answer first
  4. 14foundation · easy

    Which repository event is most commonly used to trigger a SAST scan to provide immediate feedback to developers before code is merged?

    Select an answer first
  5. 15application · medium

    A company uses Bitbucket Cloud and wants SAST scans to run on every pull request, but only on the code changes introduced by that pull request. The team wants to avoid scanning the entire codebase on every PR to save compute time. Which approach should they use?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECDE” is a trademark of its owner, used for identification only.