
EC-CouncilCertified DevSecOps Engineer
Domain 6Objective 5
Web Application Firewall (WAF) Integration ECDE Practice Questions (Page 3)
Part of the Operate and Monitor Stage domain, which makes up ~21% of our current practice bank.
51questions here
11free pages
8concepts
Questions 11–15
- 11
A company wants to validate that their WAF rules are effective against new vulnerabilities that are disclosed weekly. They have a limited security budget and cannot afford a full-time penetration tester. Which approach is most cost-effective and sustainable?
Select an answer first - 12
Which practice is commonly used to manage WAF configuration in a CI/CD pipeline?
Select an answer first - 13
A company runs a customer-facing web application behind an on-premises WAF. After a recent surge in SQL injection attempts, the security team wants to add a rule that blocks requests containing the string 'UNION SELECT' in the query string. However, the application legitimately uses a parameter named 'union_select' for a reporting feature. Which configuration approach best addresses this requirement without breaking the legitimate feature?
Select an answer first - 14
A DevSecOps team manages a web application that is deployed multiple times a day. They want to ensure that WAF rule changes are tested and deployed consistently with each application release. Which approach best integrates WAF management into their CI/CD pipeline?
Select an answer first - 15
During a security incident, the incident response team needs to determine whether a web application was exploited via an SQL injection attack. The WAF is in place. What should the team do first?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECDE” is a trademark of its owner, used for identification only.