Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified DevSecOps Engineer

Domain 2Objective 3

Scanning Code Repositories ECDE Practice Questions (Page 6)

Part of the Plan Stage: Threat Modeling and Pre-Commit Security domain, which makes up ~19% of our current practice bank.

37questions here
8free pages
9concepts

Questions 26–30

  1. 26application · medium

    A team uses Terraform to provision cloud infrastructure. They want to scan their Terraform templates for security misconfigurations before applying changes. Which tool is specifically designed for this purpose?

    Select an answer first
  2. 27expert · hard

    A company has a large legacy application with many outdated dependencies. A dependency scan reveals hundreds of vulnerabilities, but the team has limited resources to fix them. The application is internet-facing. What is the most effective prioritization strategy?

    Select an answer first
  3. 28application · medium

    A SAST scan reports 50 findings. The team has limited time to fix them before a release. They want to prioritize the most important issues. Which factor should they consider first?

    Select an answer first
  4. 29application · medium

    A team uses Kubernetes manifests stored in a Git repository. They want to scan these manifests for security misconfigurations before deployment. Which tool is best suited for this?

    Select an answer first
  5. 30foundation · easy

    Which of the following is a typical method used by secrets detection tools to identify secrets?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECDE” is a trademark of its owner, used for identification only.