
EC-CouncilCertified DevSecOps Engineer
Domain 3Objective 1
Static Application Security Testing (SAST) Concepts and Tools ECDE Practice Questions (Page 11)
Part of the Code and Build Stage: SAST and Secure Code Review domain, which makes up ~15% of our current practice bank.
53questions here
11free pages
10concepts
Questions 51–53
- 51
A DevSecOps team has implemented SAST scanning in their CI pipeline. However, the security lead notices that some business-logic flaws, such as improper authorization checks, are not being caught by the SAST tool. What is the most effective way to address this gap?
Select an answer first - 52
A SAST scan of a web application reports a critical SQL injection vulnerability in a legacy module. The development team is unsure whether the finding is a true positive because the module is rarely used. What should the team do first?
Select an answer first - 53
A development team uses GitLab CI/CD for a Python web application. They want to automatically fail the build when a new critical or high severity SAST finding is introduced, but allow the build to pass with warnings for medium and low findings. The SAST tool outputs a report in SARIF format. What is the most effective way to implement this requirement?
Select an answer first
Finished these 3 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to ECDE
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECDE” is a trademark of its owner, used for identification only.