Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified DevSecOps Engineer

Domain 2Objective 3

Scanning Code Repositories ECDE Practice Questions (Page 4)

Part of the Plan Stage: Threat Modeling and Pre-Commit Security domain, which makes up ~19% of our current practice bank.

37questions here
8free pages
9concepts

Questions 16–20

  1. 16foundation · easy

    How does Static Application Security Testing (SAST) analyze source code for vulnerabilities?

    Select an answer first
  2. 17application · medium

    A team builds a container image for a web application. They want to scan the image for vulnerabilities before pushing it to the registry. The CI pipeline currently builds the image and pushes it directly. What should they add to the pipeline?

    Select an answer first
  3. 18foundation · easy

    What is the primary purpose of dependency scanning in a code repository?

    Select an answer first
  4. 19foundation · easy

    What is the primary purpose of container image scanning?

    Select an answer first
  5. 20foundation · easy

    In a DevSecOps pipeline, repository scanning is typically performed at which stage?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECDE” is a trademark of its owner, used for identification only.