
EC-CouncilCertified DevSecOps Engineer
Domain 6Objective 5
Web Application Firewall (WAF) Integration ECDE Practice Questions (Page 8)
Part of the Operate and Monitor Stage domain, which makes up ~21% of our current practice bank.
51questions here
11free pages
8concepts
Questions 36–40
- 36
A security team wants to set up alerting for their WAF to notify them of potential attacks. They are concerned about alert fatigue from false positives. Which configuration is most effective?
Select an answer first - 37
During a security incident, the incident response team needs to determine the scope of a potential attack. The WAF logs show that a specific IP address made many requests with SQL injection payloads. What should the team do to assess the impact?
Select an answer first - 38
A DevSecOps team manages a web application that is deployed in a hybrid model: the application runs on-premises in a data center, but the team wants to use a cloud-based WAF for protection. The application's DNS is managed by an external provider. The team needs to ensure that the WAF can inspect and filter traffic before it reaches the on-premises servers. What should the team configure?
Select an answer first - 39
Which method is commonly used to simulate attack scenarios to validate WAF effectiveness?
Select an answer first - 40
During the Operate and Monitor stage, why is a WAF considered a critical security control for a web application?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECDE” is a trademark of its owner, used for identification only.