
EC-CouncilCertified DevSecOps Engineer
Domain 2Objective 4
Secret Management Tools ECDE Practice Questions (Page 2)
Part of the Plan Stage: Threat Modeling and Pre-Commit Security domain, which makes up ~19% of our current practice bank.
44questions here
9free pages
7concepts
Questions 6–10
- 6
A developer pushes a commit that accidentally includes a database password in a configuration file. The commit is merged before the mistake is noticed. The team uses GitHub Actions for CI/CD and wants to prevent this from happening again. Which approach should the team implement?
Select an answer first - 7
Which of the following is an example of a fine-grained access policy for a secret management system?
Select an answer first - 8
What is the primary purpose of secret scanning tools in a DevSecOps pipeline?
Select an answer first - 9
What is the primary purpose of secret rotation in a DevSecOps environment?
Select an answer first - 10
A development team wants to prevent hardcoded secrets from being committed to their Git repository. They use GitHub. What is the most effective way to implement this control?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECDE” is a trademark of its owner, used for identification only.