
EC-CouncilCertified DevSecOps Engineer
Domain 5Objective 2
VAPT Strategy ECDE Practice Questions (Page 9)
Part of the Release and Deploy Stage domain, which makes up ~14% of our current practice bank.
53questions here
11free pages
8concepts
Questions 41–45
- 41
Which of the following is a best practice when documenting VAPT findings?
Select an answer first - 42
A DevSecOps engineer is responsible for managing vulnerabilities found in a CI/CD pipeline. The pipeline currently fails the build on any high-severity finding, which has caused frequent release delays because of false positives. The team wants to reduce delays while still ensuring that real high-severity vulnerabilities are not deployed. What should the engineer do?
Select an answer first - 43
In a CI/CD pipeline, at which stage is it most appropriate to run an automated vulnerability scan?
Select an answer first - 44
When prioritizing vulnerabilities for remediation, which factor should be given the most weight?
Select an answer first - 45
A security team has completed a penetration test and provided a report with several high-severity findings. The development team has applied fixes. What is the next step to ensure the fixes are effective?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECDE” is a trademark of its owner, used for identification only.