
EC-CouncilCertified DevSecOps Engineer
Domain 5Objective 2
VAPT Strategy ECDE Practice Questions (Page 1)
Part of the Release and Deploy Stage domain, which makes up ~14% of our current practice bank.
53questions here
11free pages
8concepts
Questions 1–5
- 1
A vulnerability assessment identified a critical remote code execution vulnerability in a web server. The team applied a patch. What is the best way to verify that the patch is effective?
Select an answer first - 2
A company is planning a penetration test for its production environment. The test must not cause any service disruption, and the scope must be clearly defined to avoid testing third-party hosted services. Which action is most important to include in the planning phase?
Select an answer first - 3
Which of the following is a key characteristic of the PTES (Penetration Testing Execution Standard) framework?
Select an answer first - 4
A security team needs to test a network for vulnerabilities. They have a limited budget and need to cover a large number of systems. They also need to produce a report that can be used to prioritize remediation. Which tool or approach is most cost-effective?
Select an answer first - 5
A company is about to launch a new public-facing web application. The security team wants to run a penetration test before launch, but the application is still in a staging environment that is not accessible from the internet. The test must cover the application's authentication and authorization logic. What should the engineer do?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECDE” is a trademark of its owner, used for identification only.