
EC-CouncilCertified DevSecOps Engineer
Domain 6Objective 5
Web Application Firewall (WAF) Integration ECDE Practice Questions (Page 9)
Part of the Operate and Monitor Stage domain, which makes up ~21% of our current practice bank.
51questions here
11free pages
8concepts
Questions 41–45
- 41
A DevSecOps team is implementing a WAF for a new web application. They want to ensure that the WAF provides value during the Operate and Monitor stage. Which activity best demonstrates the WAF's role in this stage?
Select an answer first - 42
After deploying a WAF in front of a web application, the security team notices that legitimate users are being blocked when they submit forms that contain special characters like apostrophes. The WAF is using a managed rule set. What should the team do to reduce false positives without weakening security?
Select an answer first - 43
A company has a mix of on-premises legacy applications and cloud-based applications. They want a single WAF solution that can protect both environments with consistent policies. Which deployment model best meets this requirement?
Select an answer first - 44
After a WAF alert indicates a possible SQL injection attack, the incident response team needs to determine the scope of the attack. Which action is most important for their investigation?
Select an answer first - 45
A DevSecOps team wants to validate that their WAF rules effectively block OWASP Top 10 attacks. They have a staging environment that mirrors production. Which testing method is most appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECDE” is a trademark of its owner, used for identification only.