
EC-CouncilCertified DevSecOps Engineer
Domain 2Objective 4
Secret Management Tools ECDE Practice Questions (Page 3)
Part of the Plan Stage: Threat Modeling and Pre-Commit Security domain, which makes up ~19% of our current practice bank.
44questions here
9free pages
7concepts
Questions 11–15
- 11
In a DevSecOps context, which of the following best describes the primary purpose of secret management?
Select an answer first - 12
A company uses HashiCorp Vault to manage secrets. Their CI/CD pipeline runs on Jenkins and needs to fetch a database credential at deployment time. The security team requires that the credential is never written to the build log and that access is limited to the specific pipeline job. Which configuration should be used?
Select an answer first - 13
A startup is building a multi-cloud application that runs on both AWS and Azure. They need a central secret management solution that supports dynamic secrets, has a unified audit log, and can enforce fine-grained access policies across both clouds. Which tool should they choose?
Select an answer first - 14
A team uses Azure Key Vault to store a client secret for an application. The secret is currently set to never expire. The security team wants to enforce a maximum lifetime of 90 days and ensure that the application automatically receives the new secret after rotation. What should the team do?
Select an answer first - 15
A security auditor requires that every access to a production secret be logged with the user, timestamp, and action. The team uses HashiCorp Vault. What should they enable to meet this requirement?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECDE” is a trademark of its owner, used for identification only.