
EC-CouncilCertified DevSecOps Engineer
Domain 5Objective 2
VAPT Strategy ECDE Practice Questions (Page 4)
Part of the Release and Deploy Stage domain, which makes up ~14% of our current practice bank.
53questions here
11free pages
8concepts
Questions 16–20
- 16
A company is adopting DevSecOps and wants to ensure that security testing is not a bottleneck in their release process. They are considering how to incorporate VAPT into their release and deploy stage. What is the most effective strategy?
Select an answer first - 17
A security team is asked to assess a new web application. They have a limited time window and need to identify as many vulnerabilities as possible, but they do not need to prove exploitability. Which type of assessment should they perform?
Select an answer first - 18
A security analyst needs to identify known vulnerabilities in a set of Linux servers and then determine if any of those vulnerabilities could be exploited to gain root access. Which combination of tools is most appropriate?
Select an answer first - 19
What is the primary purpose of a VAPT report?
Select an answer first - 20
A penetration testing team is about to test a web application that handles financial transactions. They need a structured methodology that covers all phases from planning to reporting, and they want to align with industry best practices for web application testing. Which framework should they choose?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECDE” is a trademark of its owner, used for identification only.