
EC-CouncilCertified DevSecOps Engineer
Domain 5Objective 2
VAPT Strategy ECDE Practice Questions (Page 3)
Part of the Release and Deploy Stage domain, which makes up ~14% of our current practice bank.
53questions here
11free pages
8concepts
Questions 11–15
- 11
Which type of tool is primarily used to automatically identify known vulnerabilities in a system or application?
Select an answer first - 12
A DevSecOps engineer is asked to structure a penetration test for a web application that has a public-facing login portal and an internal admin API. The test must follow a recognized methodology and produce a report that maps findings to a remediation plan. Which framework should the engineer select?
Select an answer first - 13
A team wants to automatically detect misconfigurations and known vulnerabilities in their Kubernetes cluster before each release. They need a tool that can be integrated into their CI/CD pipeline and that checks both the cluster configuration and the container images. Which tool should they choose?
Select an answer first - 14
A DevSecOps engineer needs to select a vulnerability scanner for a mixed environment that includes on-premises servers, cloud VMs, and containerized workloads. The scanner must support authenticated scans and integrate with the CI/CD pipeline. Which type of scanner should the engineer choose?
Select an answer first - 15
A development team wants to integrate security testing into their CI/CD pipeline. They currently run unit tests and build artifacts. They want to catch vulnerabilities early and prevent vulnerable builds from being deployed. Which integration is most effective?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECDE” is a trademark of its owner, used for identification only.