
EC-CouncilCertified DevSecOps Engineer
Domain 2Objective 5
Software Composition Analysis (SCA) ECDE Practice Questions (Page 1)
Part of the Plan Stage: Threat Modeling and Pre-Commit Security domain, which makes up ~19% of our current practice bank.
44questions here
9free pages
9concepts
Questions 1–5
- 1
Why is it beneficial to integrate SCA scanning into the CI/CD pipeline?
Select an answer first - 2
A development team is preparing to integrate SCA into their CI pipeline. They need to ensure that the scanner can identify all vulnerable components, including those pulled in indirectly. The team has a lock file that pins exact versions of every installed package. Which action best ensures the SCA tool can map the full dependency tree to known vulnerabilities?
Select an answer first - 3
A team wants to integrate SCA into their CI pipeline, but they have a mix of applications: some are critical and some are low-risk internal tools. They want to enforce a security gate that is appropriate for each application's risk level. What is the best approach?
Select an answer first - 4
A DevOps team wants to add SCA scanning to their CI pipeline. They want to fail the build only when a critical or high severity vulnerability is found in a direct dependency. They also want to allow the pipeline to continue for medium severity issues. Which CI configuration approach meets these requirements?
Select an answer first - 5
What is the primary output of an SCA tool scan?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECDE” is a trademark of its owner, used for identification only.