Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified DevSecOps Engineer

Domain 2Objective 4

Secret Management Tools ECDE Practice Questions (Page 7)

Part of the Plan Stage: Threat Modeling and Pre-Commit Security domain, which makes up ~19% of our current practice bank.

44questions here
9free pages
7concepts

Questions 31–35

  1. 31foundation · easy

    Which of the following is an example of an access control mechanism used by secret management tools to restrict who can retrieve a secret?

    Select an answer first
  2. 32application · medium

    A CI/CD pipeline builds a Docker image and pushes it to a registry. The pipeline needs to authenticate to the registry using a token stored in Azure Key Vault. What is the recommended way to inject the token into the pipeline without exposing it in logs?

    Select an answer first
  3. 33application · medium

    A CI/CD pipeline uses Jenkins to deploy to a Kubernetes cluster. The pipeline needs to authenticate to the cluster using a service account token. What is the recommended way to store and inject the token into the Jenkins pipeline?

    Select an answer first
  4. 34application · medium

    A developer accidentally commits a private key to a Git repository and pushes it to the remote. The key is used for SSH authentication to production servers. What should the team do FIRST?

    Select an answer first
  5. 35application · medium

    A security scan of a code repository found a hardcoded API key in a commit from three months ago. The key is still valid. What is the most important action to take?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECDE” is a trademark of its owner, used for identification only.