
EC-CouncilCertified DevSecOps Engineer
Domain 2Objective 3
Scanning Code Repositories ECDE Practice Questions (Page 2)
Part of the Plan Stage: Threat Modeling and Pre-Commit Security domain, which makes up ~19% of our current practice bank.
37questions here
8free pages
9concepts
Questions 6–10
- 6
What is the purpose of scanning Infrastructure as Code (IaC) templates?
Select an answer first - 7
Which of the following is an example of a security issue that IaC scanning can detect?
Select an answer first - 8
A development team is experiencing a high rate of false positives from their SAST tool, which is causing developers to ignore the results. The security team wants to reduce the noise while maintaining security coverage. Which approach is most effective?
Select an answer first - 9
Which of the following is a characteristic of SAST tools?
Select an answer first - 10
What is the main goal of secrets detection in code repositories?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECDE” is a trademark of its owner, used for identification only.