Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified DevSecOps Engineer

Domain 3Objective 1

Static Application Security Testing (SAST) Concepts and Tools ECDE Practice Questions (Page 9)

Part of the Code and Build Stage: SAST and Secure Code Review domain, which makes up ~15% of our current practice bank.

53questions here
11free pages
10concepts

Questions 41–45

  1. 41foundation · easy

    Which statement correctly distinguishes SAST from DAST?

    Select an answer first
  2. 42application · medium

    A company has a polyglot codebase with Java, JavaScript, and Python services. They want a single SAST tool that can analyze all three languages, integrate with their Jenkins pipeline, and provide a unified dashboard for security metrics. Which tool capability is most important to evaluate first?

    Select an answer first
  3. 43foundation · easy

    At which stage of the software development lifecycle is SAST most effectively applied to identify vulnerabilities early?

    Select an answer first
  4. 44expert · hard

    A security team is designing a testing strategy for a critical web application. They have a SAST tool that scans the source code and a DAST tool that scans the running application. The team wants to detect a vulnerability that only occurs when a specific sequence of user actions is performed, such as a multi-step workflow that leads to an authorization bypass. Which testing approach is most likely to detect this vulnerability?

    Select an answer first
  5. 45foundation · easy

    How does secure code review complement automated SAST scanning?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECDE” is a trademark of its owner, used for identification only.