
EC-CouncilCertified DevSecOps Engineer
Domain 2Objective 3
Scanning Code Repositories ECDE Practice Questions (Page 7)
Part of the Plan Stage: Threat Modeling and Pre-Commit Security domain, which makes up ~19% of our current practice bank.
37questions here
8free pages
9concepts
Questions 31–35
- 31
What is the purpose of defining severity thresholds in scanning policies?
Select an answer first - 32
A DevSecOps team wants to add SAST to their CI pipeline. The application is a Java Spring Boot service with a 10-minute build. They need to fail the build on any new critical vulnerability, but they want to avoid slowing down the pipeline. The SAST tool supports incremental scanning. What is the best approach?
Select an answer first - 33
A security team wants to enforce a policy that all SAST findings must be remediated before a release. However, developers are complaining that some low-severity findings are false positives. What is the best way to handle this?
Select an answer first - 34
A team uses container images for their application. They want to enforce a policy that no image with critical vulnerabilities is deployed. However, some images are built from base images that have known critical vulnerabilities that cannot be fixed because no patched base image is available. The team wants to allow these images to be deployed while still enforcing the policy for other images. What is the best approach?
Select an answer first - 35
A development team uses a monorepo containing multiple microservices. They want to run SAST on every pull request, but the full scan takes 25 minutes, which slows down the CI pipeline. The security team wants to keep the scan comprehensive but also wants to provide fast feedback to developers. Which approach best balances these needs?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECDE” is a trademark of its owner, used for identification only.