
EC-CouncilCertified DevSecOps Engineer
Domain 2Objective 3
Scanning Code Repositories ECDE Practice Questions (Page 8)
Part of the Plan Stage: Threat Modeling and Pre-Commit Security domain, which makes up ~19% of our current practice bank.
37questions here
8free pages
9concepts
Questions 36–37
- 36
A secrets scanner is integrated into the CI pipeline and fails the build on any potential secret. A developer accidentally commits a real database password. The build fails, and the developer removes the password and pushes a new commit. What is the most important next step?
Select an answer first - 37
A team uses a dependency scanner that reports a vulnerability in a library. The library is used in a legacy service that is scheduled for decommissioning in six months. The vulnerability is critical, but the library is not directly exposed to the internet. The team wants to balance risk and effort. What is the best approach?
Select an answer first
Finished these 2 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to ECDE
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECDE” is a trademark of its owner, used for identification only.