ECCouncil EC-Council Certified DevSecOps Engineer (ECDE) - 312-97 Exam Practice Test

Question 1
A DevOps team is integrating Splunk with GitLab to monitor their CI/CD pipeline and build status. They have followed the integration steps, including installing the GitLab Add-on from Splunkbase, configuring a GitLab account with the URL and a Personal Access Token in Splunk, setting environment variables for the Splunk HTTP Event Collector (HEC) endpoint and token , and using curl commands in their GitLab pipeline to send data to Splunk. Despite completing the integration, they notice that some pipeline logs are missing in Splunk, while others appear correctly. Upon further investigation, they suspect the issue is related to data formatting and log handling in Splunk. What should the team check to resolve this issue?

Correct Answer: B
Explanation: Only visible for Actualtests4sure members. You can sign-up / login (it's free).
Question 2
Mia, a DevSecOps engineer, is responsible for ensuring that every deployment in the organization's Azure environment complies with strict security and compliance policies. Recently, a deployment introduced unapproved configurations, bypassing manual security checks and causing disruptions in the production environment. To prevent this issue from recurring, Mia needs to integrate a feature that automates compliance enforcement by evaluating policy adherence before deployment, monitoring alerts during deployment, and approval processes before and after deployment steps. Which Azure feature should Mia integrate into the release pipeline to enforce automated security and compliance checks during deployments?

Correct Answer: B
Explanation: Only visible for Actualtests4sure members. You can sign-up / login (it's free).
Question 3
John is a DevSecOps Engineer working at a software company that is implementing security early in its DevOps workflow, also known as "shifting security left." The Chief Technology Officer (CTO) and Chief Information Officer (CIO) are particularly interested in improving developer productivity while ensuring security is integrated into the development lifecycle from the start. To which category of DevSecOps stakeholders do the CTO and CIO belong?

Correct Answer: B
Explanation: Only visible for Actualtests4sure members. You can sign-up / login (it's free).
Question 4
CloudSync, a cloud-based SaaS provider, experienced a cyber-attack, where attackers exploited a vulnerability in its web application and gained unauthorized access to critical features. After containing the incident, the DevSecOps team conducted an in-depth analysis of the attack, identified the root cause, implemented necessary security fixes, and documented lessons learned to prevent similar issues in the future. Which of the following best describes the type of security assessment conducted by CloudSync's DevSecOps team?

Correct Answer: C
Explanation: Only visible for Actualtests4sure members. You can sign-up / login (it's free).
Question 5
Steven Smith has been working as a DevSecOps engineer in an IT company that develops software products related to the financial sector. His team leader asked him to integrate Conjur with Jenkins to secure the secret credentials. Therefore, Steven downloaded Conjur.hpi file and uploaded it in the Upload Plugin section of Jenkins. He declared host and layers, and declared the variables. Which of the following commands should Steven use to set the value of variables?

Correct Answer: D
Explanation: Only visible for Actualtests4sure members. You can sign-up / login (it's free).
Question 6
Terry Crews has been working as a DevSecOps engineer at an IT company that develops software products and web applications related to IoT devices. She integrated Sqreen RASP tool with Slack for sending notifications related to security issues to her team. How can Sqreen send notification alerts to Slack?

Correct Answer: A
Explanation: Only visible for Actualtests4sure members. You can sign-up / login (it's free).
Question 7
Sophia, a DevSecOps engineer, is working on improving the security posture of her organization's cloud-native applications. She wants to integrate continuous threat modeling directly into the software development process to ensure that developers can identify security risks while writing code. To achieve this, she introduces a tool that allows developers to annotate source code with security concerns, generate data flow diagrams (DFDs), and create threat model reports dynamically. This approach enables real-time visibility into security risks and bridges the gap between development and security teams. Which tool should Sophia use to achieve this?

Correct Answer: D
Explanation: Only visible for Actualtests4sure members. You can sign-up / login (it's free).
Question 8
A cloud operations team manages a fleet of virtual machines (VMs) in Google Cloud Platform (GCP). The team wants to automate OS patching across all VM instances without manual intervention, ensure compliance by keeping all VMs up to date with the latest security patches and monitor and manage software configurations across multiple VM instances efficiently. To achieve these goals, the team decides to leverage a GCP service that provides centralized patch management, configuration enforcement, and automation. Which GCP service should the team use?

Correct Answer: D
Explanation: Only visible for Actualtests4sure members. You can sign-up / login (it's free).