Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified DevSecOps Engineer

Domain 3Objective 1

Static Application Security Testing (SAST) Concepts and Tools ECDE Practice Questions (Page 11)

Part of the Code and Build Stage: SAST and Secure Code Review domain, which makes up ~15% of our current practice bank.

53questions here
11free pages
10concepts

Questions 51–53

  1. 51application · medium

    A DevSecOps team has implemented SAST scanning in their CI pipeline. However, the security lead notices that some business-logic flaws, such as improper authorization checks, are not being caught by the SAST tool. What is the most effective way to address this gap?

    Select an answer first
  2. 52application · medium

    A SAST scan of a web application reports a critical SQL injection vulnerability in a legacy module. The development team is unsure whether the finding is a true positive because the module is rarely used. What should the team do first?

    Select an answer first
  3. 53application · medium

    A development team uses GitLab CI/CD for a Python web application. They want to automatically fail the build when a new critical or high severity SAST finding is introduced, but allow the build to pass with warnings for medium and low findings. The SAST tool outputs a report in SARIF format. What is the most effective way to implement this requirement?

    Select an answer first
Finished these 3 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to ECDE

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECDE” is a trademark of its owner, used for identification only.