
Certified Tester Quality in DevOps
Domain 4Objective 4
Observability and Compliance CT-QDO Practice Questions (Page 3)
Part of the Domain 4: Tools and Practices in DevOps domain, which makes up ~19% of our current practice bank. ISTQB does not publish an official question count, but from its 60-minute exam (~25–40 total, ~5–8 in this domain), expect 1–2 from this objective — we provide 33 practice questions to prepare you well beyond it. (estimate)
33questions here
7free pages
7concepts
Questions 11–15
- 11
A company must provide an SBOM for a product that includes both proprietary code and third-party components. The legal team requires that the SBOM be accurate but also wants to avoid exposing proprietary code details. Which approach is most appropriate?
Select an answer first - 12
What role do SBOMs play in ensuring compliance in DevOps?
Select an answer first - 13
A DevOps team is designing a monitoring solution for a new application. They want to ensure that when a user reports a problem, they can see the exact sequence of events leading up to the issue. Which observability pillar is most directly responsible for providing this chronological view?
Select an answer first - 14
How are SBOMs used in vulnerability management?
Select an answer first - 15
A DevOps team wants to automate the generation of SBOMs for every build and store them as artifacts. Their goal is to quickly identify which deployed version of an application contains a specific vulnerable library. Which practice best supports this goal?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISTQB. “CT-QDO” is a trademark of its owner, used for identification only.