
EC-CouncilCertified DevSecOps Engineer
Domain 6Objective 5
Web Application Firewall (WAF) Integration ECDE Practice Questions (Page 10)
Part of the Operate and Monitor Stage domain, which makes up ~21% of our current practice bank.
51questions here
11free pages
8concepts
Questions 46–50
- 46
A DevSecOps team is integrating WAF rule updates into their CI/CD pipeline. They have a staging environment that mirrors production. The team wants to automatically test WAF rule changes against a set of known attack payloads and a set of legitimate traffic samples before promoting to production. What is the best approach?
Select an answer first - 47
What is the purpose of a WAF policy in the context of protecting a web application?
Select an answer first - 48
A multinational company operates a web application that must comply with data residency requirements. The application is hosted in a public cloud region in the EU, but the company is considering using a cloud-based WAF that only has points of presence (PoPs) in the US. The security team is concerned about whether the WAF will handle EU user data in a compliant manner. What should the team do?
Select an answer first - 49
A WAF administrator is tuning rules to reduce false positives. They notice that a rule blocks requests with a certain User-Agent string that is used by a legitimate monitoring service. However, the same User-Agent is also used by a known botnet. What is the best approach to handle this conflict?
Select an answer first - 50
A company is deploying a WAF for a web application that is hosted in a private cloud on-premises. The company wants to use a cloud-based WAF service to protect the application. The application's DNS is managed by the company's IT team. What is the primary integration consideration?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECDE” is a trademark of its owner, used for identification only.