
EC-CouncilCertified DevSecOps Engineer
Domain 3Objective 1
Static Application Security Testing (SAST) Concepts and Tools ECDE Practice Questions (Page 1)
Part of the Code and Build Stage: SAST and Secure Code Review domain, which makes up ~15% of our current practice bank.
53questions here
11free pages
10concepts
Questions 1–5
- 1
A DevSecOps team is integrating a SAST tool into their CI pipeline. The tool produces a large number of false positives, and developers are starting to ignore the scan results. The team wants to improve the effectiveness of the SAST process without losing visibility into real issues. Which action should the team take first?
Select an answer first - 2
Which of the following is a widely used SAST tool?
Select an answer first - 3
A development team is building a REST API that handles user authentication. They run a SAST scan and a DAST scan. The SAST scan reports a potential SQL injection in a database query, while the DAST scan does not detect it. The team is confused about why the DAST scan missed it. Which is the most likely reason?
Select an answer first - 4
What is the primary benefit of integrating SAST into the CI/CD pipeline?
Select an answer first - 5
A DevSecOps engineer is configuring a CI/CD pipeline for a Java Spring Boot application. The team wants to fail the build only when a critical or high-severity vulnerability is found in the new code committed in the pull request, while allowing existing medium-severity issues in legacy code to remain visible in the report without blocking the pipeline. The SAST tool supports incremental scanning and quality gates. Which configuration approach should the engineer use?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECDE” is a trademark of its owner, used for identification only.