
EC-CouncilCertified DevSecOps Engineer
Domain 2Objective 2
Pre-Commit Code Evaluation ECDE Practice Questions (Page 6)
Part of the Plan Stage: Threat Modeling and Pre-Commit Security domain, which makes up ~19% of our current practice bank.
50questions here
10free pages
10concepts
Questions 26–30
- 26
A development team is adopting a new security linter for their Python codebase. The linter flags a large number of issues, many of which are style-related or are known false positives for their specific framework. The team wants to enforce the linter in pre-commit hooks, but they are concerned about overwhelming developers and slowing down the commit process. What is the best initial strategy?
Select an answer first - 27
In a CI/CD pipeline, what is the benefit of integrating pre-commit security tools as an early stage?
Select an answer first - 28
A company is developing a Java application that uses several open-source libraries. The security team wants to enforce a policy that no library with a known critical vulnerability (CVSS score >= 9.0) can be added to the codebase. They also want to ensure that the policy is enforced before code is merged into the main branch. Which combination of actions is most effective?
Select an answer first - 29
Which statement best describes the role of pre-commit code evaluation in a DevSecOps pipeline?
Select an answer first - 30
Which of the following is a best practice for managing secrets in application code?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECDE” is a trademark of its owner, used for identification only.