Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified DevSecOps Engineer

Domain 2Objective 3

Scanning Code Repositories ECDE Practice Questions (Page 1)

Part of the Plan Stage: Threat Modeling and Pre-Commit Security domain, which makes up ~19% of our current practice bank.

37questions here
8free pages
9concepts

Questions 1–5

  1. 1application · medium

    A secrets scanner is integrated into the CI pipeline and fails the build when a potential secret is found. A developer accidentally commits a test API key that is not a real credential. The build fails. What should the developer do?

    Select an answer first
  2. 2foundation · easy

    Which of the following best describes what dependency scanning tools typically check?

    Select an answer first
  3. 3expert · hard

    A container image scanning tool reports a vulnerability in a package that is installed but not used by the application. The team wants to reduce the attack surface and minimize false positives. What is the best approach?

    Select an answer first
  4. 4application · medium

    A Java application uses a library with a known critical vulnerability. The dependency scanner flags it, but the library is used in a non-network-facing module. The security team wants to enforce a policy that does not block the release but still tracks the issue. Which policy configuration best fits this requirement?

    Select an answer first
  5. 5foundation · easy

    What is the primary benefit of integrating scanning tools into a CI/CD pipeline?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECDE” is a trademark of its owner, used for identification only.