
EC-CouncilCertified DevSecOps Engineer
Domain 5Objective 1
Runtime Application Self-Protection (RASP) ECDE Practice Questions (Page 4)
Part of the Release and Deploy Stage domain, which makes up ~14% of our current practice bank.
51questions here
11free pages
9concepts
Questions 16–20
- 16
A security analyst is comparing RASP and WAF capabilities for a new application deployment. The application has a critical vulnerability in a custom XML parser that processes user-supplied files. The team needs protection that can detect and block the attack at the exact moment the vulnerable code executes. Which statement correctly describes the advantage of RASP over WAF in this scenario?
Select an answer first - 17
What is the first step in an incident response process when RASP detects a threat in production?
Select an answer first - 18
A team is deploying RASP to a large portfolio of applications. They want to minimize the operational overhead of managing RASP policies while ensuring each application is protected. The team has a mix of legacy and modern applications. Which approach best balances policy management and protection?
Select an answer first - 19
What is a key strategy for tuning RASP policies to minimize false positives while maintaining security?
Select an answer first - 20
A team has deployed RASP in blocking mode for a web application. During a routine penetration test, the testers successfully exploited a stored XSS vulnerability, and RASP did not block the attack. The team needs to understand why RASP missed the attack and how to fix it. What is the most likely cause and the appropriate action?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECDE” is a trademark of its owner, used for identification only.