
EC-CouncilCertified DevSecOps Engineer
Domain 5Objective 2
VAPT Strategy ECDE Practice Questions (Page 6)
Part of the Release and Deploy Stage domain, which makes up ~14% of our current practice bank.
53questions here
11free pages
8concepts
Questions 26–30
- 26
A company has a large number of vulnerabilities identified in a recent assessment. The security team has limited resources and cannot fix all of them immediately. Management wants to reduce the overall risk as quickly as possible. What is the most effective strategy?
Select an answer first - 27
Which VAPT framework is specifically focused on web application security and provides a testing guide that is widely used by penetration testers?
Select an answer first - 28
During VAPT planning, what is the purpose of defining the testing window?
Select an answer first - 29
A security manager wants to identify all known vulnerabilities in a legacy internal application before a planned upgrade. The goal is to get a comprehensive list of weaknesses with severity ratings, not to validate whether any of them can be exploited. The testing must not disrupt the application. Which type of assessment should be performed?
Select an answer first - 30
A team wants to add automated security testing to their CI/CD pipeline. They need to catch common web vulnerabilities in each build without slowing down the pipeline, and they want the results to be available to developers in the pull-request view. Which integration should they implement?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECDE” is a trademark of its owner, used for identification only.