
EC-CouncilCertified DevSecOps Engineer
Domain 2Objective 2
Pre-Commit Code Evaluation ECDE Practice Questions (Page 4)
Part of the Plan Stage: Threat Modeling and Pre-Commit Security domain, which makes up ~19% of our current practice bank.
50questions here
10free pages
10concepts
Questions 16–20
- 16
An organization uses a self-hosted Git server. They want to enforce pre-commit security checks, but some developers work in environments where they cannot install additional tools locally. They need a solution that works for all developers without requiring local installation. What is the best approach?
Select an answer first - 17
How can pre-commit checks enforce organizational security policies?
Select an answer first - 18
A startup is building a new microservices application. The CTO wants to ensure that security checks are performed as early as possible in the development lifecycle. The team is currently using Git with a central repository and has a CI system that runs after code is pushed. Which statement best describes the value of adding pre-commit code evaluation in addition to the existing CI checks?
Select an answer first - 19
A security engineer discovers that a hardcoded database password was committed to the repository two weeks ago and has been pushed to the remote. The password is for a production database. The engineer needs to remediate this issue. Which sequence of actions is most appropriate?
Select an answer first - 20
A team uses a monorepo with multiple services in different languages (Python, Go, and JavaScript). They want to enforce a pre-commit hook that runs a language-appropriate SAST tool on only the files that have been staged for commit. The hook must not take more than a few seconds to run and must not produce false positives that block legitimate commits. Which configuration approach is most appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECDE” is a trademark of its owner, used for identification only.