
EC-CouncilCertified DevSecOps Engineer
Domain 3Objective 2
Integrating the Code Repo to SAST Tools ECDE Practice Questions (Page 4)
Part of the Code and Build Stage: SAST and Secure Code Review domain, which makes up ~15% of our current practice bank.
30questions here
6free pages
5concepts
Questions 16–20
- 16
A team uses GitHub and wants to run SAST scans on pull request updates, but not on the initial pull request creation. The SAST tool integrates via webhook. Which webhook event should the team subscribe to?
Select an answer first - 17
A team uses Jenkins for CI/CD and wants to integrate a SAST tool so that scans run automatically as part of the build pipeline for every commit pushed to the main branch. The SAST tool provides a Jenkins plugin and a REST API. Which integration method is most appropriate for this scenario?
Select an answer first - 18
A security team is configuring a SAST tool to connect to a self-hosted GitLab instance. The SAST tool needs read access to all repositories in the 'development' group but must not be able to modify code or access other groups. Which configuration approach satisfies the least-privilege requirement?
Select an answer first - 19
A team uses GitHub and wants to run SAST scans on pull requests, but only when the PR modifies files in the 'src' directory. They also want to post a comment on the PR with the scan results. The SAST tool supports webhooks and a GitHub App. Which configuration should the team implement?
Select an answer first - 20
A SAST tool needs to access a private repository in GitHub. The team wants to use a token that is automatically rotated and has the minimum permissions required for read-only access. Which token type should the team use?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECDE” is a trademark of its owner, used for identification only.