Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified DevSecOps Engineer

Domain 2Objective 2

Pre-Commit Code Evaluation ECDE Practice Questions (Page 3)

Part of the Plan Stage: Threat Modeling and Pre-Commit Security domain, which makes up ~19% of our current practice bank.

50questions here
10free pages
10concepts

Questions 11–15

  1. 11foundation · easy

    Which of the following is a common vulnerability that SAST tools are designed to detect?

    Select an answer first
  2. 12expert · hard

    A security team is implementing a pre-commit SAST tool. They are concerned about the tool's false positive rate, which is currently 30%. They want to reduce this to below 10% without losing coverage of real vulnerabilities. Which approach is most effective?

    Select an answer first
  3. 13foundation · easy

    How does Static Application Security Testing (SAST) analyze source code for vulnerabilities?

    Select an answer first
  4. 14application · medium

    A team uses GitHub Actions for CI/CD. They want to run SAST on every pull request and block merging if critical vulnerabilities are found. They also want to avoid running the full scan on documentation-only changes. Which configuration best meets these requirements?

    Select an answer first
  5. 15application · medium

    A team has a pre-commit hook that runs a SAST tool. The tool is producing a high number of false positives, which is causing developers to use the `--no-verify` flag to bypass the hook. The security lead wants to reduce false positives without losing coverage of real vulnerabilities. Which approach is most effective?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECDE” is a trademark of its owner, used for identification only.