
EC-CouncilCertified DevSecOps Engineer
Domain 3Objective 1
Static Application Security Testing (SAST) Concepts and Tools ECDE Practice Questions (Page 10)
Part of the Code and Build Stage: SAST and Secure Code Review domain, which makes up ~15% of our current practice bank.
53questions here
11free pages
10concepts
Questions 46–50
- 46
A company has a large codebase written in Java, C#, and JavaScript. They are evaluating SAST tools and want a single tool that can scan all three languages, integrate with their Jenkins CI server, and provide a centralized reporting dashboard. Which tool selection would best meet these requirements?
Select an answer first - 47
How are SAST tools typically integrated into a CI/CD pipeline to automate security checks?
Select an answer first - 48
Which type of security issue is SAST generally unable to detect?
Select an answer first - 49
A company is evaluating SAST tools for a large codebase that includes C++, Java, and JavaScript. They need a tool that can be integrated into their existing CI/CD pipeline and provide detailed reports for compliance audits. The security team is concerned about the tool's ability to handle large codebases without slowing down the pipeline. Which feature is most important to evaluate?
Select an answer first - 50
A DevSecOps team is selecting a SAST tool for a polyglot codebase that includes Python, Go, and Ruby. They need the tool to integrate with their GitLab CI pipeline and provide a way to enforce security gates. Which tool capability is most important to verify before making the selection?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECDE” is a trademark of its owner, used for identification only.