
EC-CouncilCertified DevSecOps Engineer
Domain 3Objective 1
Static Application Security Testing (SAST) Concepts and Tools ECDE Practice Questions (Page 8)
Part of the Code and Build Stage: SAST and Secure Code Review domain, which makes up ~15% of our current practice bank.
53questions here
11free pages
10concepts
Questions 36–40
- 36
What is the primary purpose of a secure code review?
Select an answer first - 37
A security team is evaluating SAST results for a legacy Java application. The SAST tool reports a high number of findings in a module that handles user input, but many are flagged as 'potential' issues. The team is concerned about wasting developer time on false positives. What is the best approach to handle this situation?
Select an answer first - 38
A startup with a small development team wants to improve code security without slowing down development. They are considering whether to rely on automated SAST tools or manual code reviews. What is the most balanced approach?
Select an answer first - 39
A development team is integrating SAST into their CI pipeline. They want to ensure that developers receive feedback quickly, but the full SAST scan takes 30 minutes. The team is considering running SAST on every commit. What is the best approach to balance speed and coverage?
Select an answer first - 40
Which SAST tool is known for its ability to scan source code and identify security vulnerabilities in multiple programming languages, and is often used in enterprise environments?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECDE” is a trademark of its owner, used for identification only.