
EC-CouncilCertified DevSecOps Engineer
Domain 5Objective 2
VAPT Strategy ECDE Practice Questions (Page 5)
Part of the Release and Deploy Stage domain, which makes up ~14% of our current practice bank.
53questions here
11free pages
8concepts
Questions 21–25
- 21
A security team has a limited budget and needs to assess a new web application before launch. The application is internet-facing and handles sensitive user data. The team wants to identify exploitable vulnerabilities that could lead to data breach, but they also need to produce a report that demonstrates due diligence to regulators. Which assessment approach should they choose?
Select an answer first - 22
What is the main benefit of integrating vulnerability scanning into a CI/CD pipeline?
Select an answer first - 23
After a penetration test, the security team has a list of findings. Management wants to know which vulnerabilities to fix first. The team has identified a critical SQL injection in the main application, a medium-severity misconfiguration in a non-critical internal tool, and a low-severity information disclosure in an error page. What should the team do?
Select an answer first - 24
Which of the following is a critical element to include in the scope definition of a VAPT engagement?
Select an answer first - 25
A DevSecOps team wants to add automated security testing to their CI/CD pipeline for a web application. They need to catch common web vulnerabilities (e.g., SQLi, XSS) in each build without slowing down the pipeline significantly. They also want to run a deeper manual-style test only on release candidates. Which approach best meets these requirements?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECDE” is a trademark of its owner, used for identification only.