
EC-CouncilCertified DevSecOps Engineer
Domain 3Objective 1
Static Application Security Testing (SAST) Concepts and Tools ECDE Practice Questions (Page 4)
Part of the Code and Build Stage: SAST and Secure Code Review domain, which makes up ~15% of our current practice bank.
53questions here
11free pages
10concepts
Questions 16–20
- 16
A large organization has multiple development teams using different CI/CD platforms (Jenkins, GitLab CI, and Azure DevOps). They want to enforce a consistent SAST policy across all teams, including severity thresholds and reporting. The security team has limited resources and cannot maintain custom integrations for each platform. What is the most effective approach?
Select an answer first - 17
A DevSecOps engineer is designing a security testing strategy for a Java microservices application. The team wants to catch vulnerabilities as early as possible in the development cycle, but they also need to identify issues that only manifest when the application is running, such as authentication bypasses and insecure server configuration. Which combination of testing approaches best meets both requirements?
Select an answer first - 18
When prioritizing SAST findings, which factor should be considered first?
Select an answer first - 19
What is a key strength of manual code review compared to automated SAST tools?
Select an answer first - 20
A SAST scan reports a critical finding in a third-party library that is used across multiple applications. The library is no longer maintained, and the team cannot upgrade to a patched version. What is the most appropriate remediation workflow?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECDE” is a trademark of its owner, used for identification only.