
EC-CouncilCertified DevSecOps Engineer
Domain 3Objective 1
Static Application Security Testing (SAST) Concepts and Tools ECDE Practice Questions (Page 9)
Part of the Code and Build Stage: SAST and Secure Code Review domain, which makes up ~15% of our current practice bank.
53questions here
11free pages
10concepts
Questions 41–45
- 41
Which statement correctly distinguishes SAST from DAST?
Select an answer first - 42
A company has a polyglot codebase with Java, JavaScript, and Python services. They want a single SAST tool that can analyze all three languages, integrate with their Jenkins pipeline, and provide a unified dashboard for security metrics. Which tool capability is most important to evaluate first?
Select an answer first - 43
At which stage of the software development lifecycle is SAST most effectively applied to identify vulnerabilities early?
Select an answer first - 44
A security team is designing a testing strategy for a critical web application. They have a SAST tool that scans the source code and a DAST tool that scans the running application. The team wants to detect a vulnerability that only occurs when a specific sequence of user actions is performed, such as a multi-step workflow that leads to an authorization bypass. Which testing approach is most likely to detect this vulnerability?
Select an answer first - 45
How does secure code review complement automated SAST scanning?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECDE” is a trademark of its owner, used for identification only.