
EC-CouncilCertified DevSecOps Engineer
Domain 3Objective 2
Integrating the Code Repo to SAST Tools ECDE Practice Questions (Page 6)
Part of the Code and Build Stage: SAST and Secure Code Review domain, which makes up ~15% of our current practice bank.
30questions here
6free pages
5concepts
Questions 26–30
- 26
Which security best practice should be applied when storing credentials used by a SAST tool to connect to a code repository?
Select an answer first - 27
How can SAST scan results be integrated into the development workflow to provide feedback to developers?
Select an answer first - 28
A SAST tool configuration includes a field to specify 'include only the main and develop branches'. What is this field called?
Select an answer first - 29
A development team uses GitHub Enterprise for source control and wants to run a SAST scan automatically every time a developer pushes code to any branch in the 'main' repository. The SAST tool is a self-hosted service that supports webhooks and a REST API. The team wants to avoid exposing the SAST tool's admin credentials to the CI/CD pipeline. Which integration method should the team configure?
Select an answer first - 30
Which integration method allows a SAST tool to receive real-time notifications from a code repository whenever a specific event, such as a push or pull request, occurs?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to ECDE
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECDE” is a trademark of its owner, used for identification only.