Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified DevSecOps Engineer

Domain 2Objective 4

Secret Management Tools ECDE Practice Questions (Page 5)

Part of the Plan Stage: Threat Modeling and Pre-Commit Security domain, which makes up ~19% of our current practice bank.

44questions here
9free pages
7concepts

Questions 21–25

  1. 21application · medium

    A company uses a mix of AWS and on-premises servers. They need a secret management solution that can store secrets, provide dynamic database credentials, and integrate with both AWS and on-premises workloads. Which tool is best suited for this hybrid environment?

    Select an answer first
  2. 22application · medium

    A GitLab CI/CD pipeline needs to access a secret stored in HashiCorp Vault. The team wants to avoid storing the Vault token in the pipeline configuration. What is the recommended approach?

    Select an answer first
  3. 23application · medium

    During a code review, a developer accidentally committed an AWS access key to a public GitHub repository. The key was exposed for 48 hours before being noticed. What is the FIRST action the team should take?

    Select an answer first
  4. 24application · medium

    A DevSecOps team is deploying a microservices application to AWS. They need to store database credentials and API keys, automatically rotate them, and inject them into containers at runtime without baking them into images. Which solution best meets these requirements?

    Select an answer first
  5. 25application · medium

    A developer is about to commit code that contains a hardcoded database password. Which of the following is the BEST way to prevent this from happening?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECDE” is a trademark of its owner, used for identification only.