
EC-CouncilCertified DevSecOps Engineer
Domain 6Objective 5
Web Application Firewall (WAF) Integration ECDE Practice Questions (Page 1)
Part of the Operate and Monitor Stage domain, which makes up ~21% of our current practice bank.
51questions here
11free pages
8concepts
Questions 1–5
- 1
A security operations center (SOC) is overwhelmed by WAF alerts. Most alerts are false positives caused by legitimate application behavior. The SOC team wants to reduce alert noise while ensuring that real attacks are not missed. What should they do?
Select an answer first - 2
A company has deployed a WAF and wants to validate that it is not blocking legitimate traffic. They have a set of recorded production traffic that is known to be benign. What should they do?
Select an answer first - 3
A DevOps team uses a CI/CD pipeline to deploy a web application. They want to manage WAF rules as code and automatically update the WAF when the application changes. The team uses Git for version control and wants to review changes before they are applied to production. What is the best approach?
Select an answer first - 4
A security team wants to set up WAF monitoring to detect brute-force attacks against a login page. They want to be alerted when there are many failed login attempts from a single IP address. What should they configure?
Select an answer first - 5
A company wants to protect both its on-premises legacy application and a new cloud-hosted application with a single WAF solution. Which deployment model is most appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECDE” is a trademark of its owner, used for identification only.