
EC-CouncilCertified DevSecOps Engineer
Domain 5Objective 1
Runtime Application Self-Protection (RASP) ECDE Practice Questions (Page 10)
Part of the Release and Deploy Stage domain, which makes up ~14% of our current practice bank.
51questions here
11free pages
9concepts
Questions 46–50
- 46
A SOC analyst is investigating a potential breach. The RASP logs show that an attacker attempted to exploit a path traversal vulnerability, but the attack was blocked. The analyst needs to provide a detailed report to management. Which information from the RASP logs is most important to include in the report?
Select an answer first - 47
A DevSecOps team is deploying a containerized Java microservice behind an existing WAF. The security lead wants to detect and block SQL injection attempts that reach the application logic after the WAF has already passed the request. The team cannot modify the application source code. Which approach best meets this requirement?
Select an answer first - 48
A DevSecOps team is integrating RASP into their CI/CD pipeline. The team has a multi-stage pipeline: build, test, staging, and production. They want to ensure that RASP is deployed consistently across all environments and that policies are managed centrally. The team is considering using infrastructure as code (IaC) to manage RASP deployment. What is the most effective approach?
Select an answer first - 49
What is a common practice for integrating RASP into a CI/CD pipeline?
Select an answer first - 50
A team is deploying a new Java application to a Kubernetes cluster. They want to use RASP but are concerned about the overhead of running an agent in each pod. They are considering an embedded RASP library that is compiled into the application. What is a key trade-off of this approach?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECDE” is a trademark of its owner, used for identification only.