
EC-CouncilCertified DevSecOps Engineer
Domain 3Objective 1
Static Application Security Testing (SAST) Concepts and Tools ECDE Practice Questions (Page 7)
Part of the Code and Build Stage: SAST and Secure Code Review domain, which makes up ~15% of our current practice bank.
53questions here
11free pages
10concepts
Questions 31–35
- 31
Which of the following is a key capability of SAST tools?
Select an answer first - 32
Which practice helps align SAST with development workflows?
Select an answer first - 33
A development team is implementing a secure code review process. They have a SAST tool that scans every commit and a manual review process that is performed by senior developers. The team is debating how to allocate review effort. The SAST tool has a high false-positive rate, and the senior developers are spending too much time reviewing false positives. Which approach would best improve the efficiency of the manual review process?
Select an answer first - 34
A security team is evaluating the results of a SAST scan on a legacy Java application. The scan reports 500 findings, of which 400 are in code that is no longer actively maintained, and 100 are in actively developed code. The team has limited remediation resources and wants to reduce risk most effectively. The application is scheduled to be replaced in 12 months. Which approach should the team take?
Select an answer first - 35
A DevSecOps team is struggling with a high volume of SAST findings, many of which are false positives. Developers are becoming desensitized and may ignore real issues. The team wants to reduce noise without losing true positives. What is the most effective strategy?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECDE” is a trademark of its owner, used for identification only.