
EC-CouncilCertified DevSecOps Engineer
Domain 5Objective 2
VAPT Strategy ECDE Practice Questions (Page 2)
Part of the Release and Deploy Stage domain, which makes up ~14% of our current practice bank.
53questions here
11free pages
8concepts
Questions 6–10
- 6
A penetration test has been completed, and the report contains a critical finding with a proof-of-concept exploit. The development team asks for the raw exploit code to reproduce the issue. What should the DevSecOps engineer do?
Select an answer first - 7
A security team is planning the first VAPT engagement for a new customer-facing web portal. Management wants a broad, automated check for known vulnerabilities across the entire infrastructure, but also wants to know if a real attacker could chain vulnerabilities to gain unauthorized access to customer data. The budget allows for one engagement. What should the team do?
Select an answer first - 8
Which statement best describes the role of VAPT in a DevSecOps release pipeline?
Select an answer first - 9
A penetration test report contains a finding that was verified as a false positive by the development team. The security team disagrees and believes it is a real vulnerability. The report is due to be submitted to the compliance team next week. What should the DevSecOps engineer do?
Select an answer first - 10
A penetration testing team is asked to test a web application that is hosted in a cloud environment. The team is not familiar with the cloud provider's specific services. They need a methodology that will help them understand the application's architecture and identify potential attack vectors. Which approach is most effective?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECDE” is a trademark of its owner, used for identification only.