
EC-CouncilCertified DevSecOps Engineer
Domain 5Objective 2
VAPT Strategy ECDE Practice Questions (Page 8)
Part of the Release and Deploy Stage domain, which makes up ~14% of our current practice bank.
53questions here
11free pages
8concepts
Questions 36–40
- 36
A security team is planning a penetration test for a critical infrastructure system. The system is regulated, and the test must not impact availability. The team has a limited testing window and needs to produce a report that satisfies the regulator. Which methodology should they use?
Select an answer first - 37
Which of the following tools is commonly used for manual web application penetration testing?
Select an answer first - 38
Which of the following best describes the scope of a penetration test compared to a vulnerability assessment?
Select an answer first - 39
In the context of the release and deploy stage, what is the primary purpose of a VAPT strategy?
Select an answer first - 40
A penetration tester is assigned to test a web application that uses both REST APIs and a GraphQL endpoint. The tester needs a methodology that provides detailed guidance for testing GraphQL-specific vulnerabilities. Which framework should the tester consult?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECDE” is a trademark of its owner, used for identification only.