
EC-CouncilCertified DevSecOps Engineer
Domain 3Objective 1
Static Application Security Testing (SAST) Concepts and Tools ECDE Practice Questions (Page 3)
Part of the Code and Build Stage: SAST and Secure Code Review domain, which makes up ~15% of our current practice bank.
53questions here
11free pages
10concepts
Questions 11–15
- 11
A DevSecOps team wants to ensure that SAST findings are not ignored by developers. They plan to integrate SAST into their CI pipeline and want to enforce a policy where critical and high findings must be fixed before a merge. What is the best way to implement this?
Select an answer first - 12
What is a best practice for managing false positives in SAST results?
Select an answer first - 13
A security team is triaging SAST findings for a web application. The scan reports a critical-severity SQL injection in a function that is called from a public-facing endpoint. The team also finds a medium-severity XSS issue in an internal admin panel that is only accessible to authenticated administrators. The team has limited resources and can only fix one issue this sprint. Which issue should the team fix first?
Select an answer first - 14
A DevSecOps team is deciding how to allocate limited security review resources between automated SAST and manual code review. The application is a customer-facing web app with high regulatory requirements. The team has found that SAST catches common issues but misses business-logic flaws. What is the most effective allocation of resources?
Select an answer first - 15
A security team is evaluating SAST tools for a Ruby on Rails application. They need a tool that can be easily integrated into their GitHub Actions workflow and provides a simple way to report findings to developers. Which tool is most appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECDE” is a trademark of its owner, used for identification only.