
EC-CouncilCertified DevSecOps Engineer
Domain 2Objective 4
Secret Management Tools ECDE Practice Questions (Page 1)
Part of the Plan Stage: Threat Modeling and Pre-Commit Security domain, which makes up ~19% of our current practice bank.
44questions here
9free pages
7concepts
Questions 1–5
- 1
A security team is implementing secret rotation for a service account used by a batch job that runs every hour. The rotation policy must ensure that the service account password is rotated every 30 days, but the batch job must not fail due to a rotated password. The job reads the password from a file at startup. What is the best approach?
Select an answer first - 2
A company discovers that a database password has been exposed in a public GitHub repository for the past six months. The password is used by multiple applications. What is the FIRST action the team should take?
Select an answer first - 3
A security auditor requires that all access to secrets in AWS Secrets Manager be logged, including who accessed the secret and from which IP address. Which service should be used to meet this requirement?
Select an answer first - 4
A company is evaluating secret management solutions and requires that secrets be encrypted with customer-managed keys (CMK) and that access be auditable. Which solution meets both requirements?
Select an answer first - 5
A security team needs to audit who accessed a specific secret in AWS Secrets Manager over the past 90 days. They have CloudTrail enabled. What is the most efficient way to retrieve this information?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECDE” is a trademark of its owner, used for identification only.