최신ECCouncil EC-Council Certified DevSecOps Engineer (ECDE) - 312-97무료샘플문제
문제1
Emma is a DevSecOps engineer at a software company that primarily develops Java-based applications. The development team frequently encounters inconsistent builds, dependency management issues, and difficulties in tracking project artifacts. Emma's project manager after consideration recommends using Apache Maven to be integrated to their project pipeline. Which of the following is the key advantage of using Apache Maven in a DevSecOps environment?
Emma is a DevSecOps engineer at a software company that primarily develops Java-based applications. The development team frequently encounters inconsistent builds, dependency management issues, and difficulties in tracking project artifacts. Emma's project manager after consideration recommends using Apache Maven to be integrated to their project pipeline. Which of the following is the key advantage of using Apache Maven in a DevSecOps environment?
정답: A
설명: (KoreaDumps 회원만 볼 수 있음)
문제2
Terry Crews has been working as a DevSecOps engineer at an IT company that develops software products and web applications related to IoT devices. She integrated Sqreen RASP tool with Slack for sending notifications related to security issues to her team. How can Sqreen send notification alerts to Slack?
Terry Crews has been working as a DevSecOps engineer at an IT company that develops software products and web applications related to IoT devices. She integrated Sqreen RASP tool with Slack for sending notifications related to security issues to her team. How can Sqreen send notification alerts to Slack?
정답: D
설명: (KoreaDumps 회원만 볼 수 있음)
문제3
A healthcare organization recently suffered a security breach due to an exposed SSH key in one of its public Git repositories. To prevent similar incidents, the DevSecOps team decides to enforce a security mechanism that blocks sensitive information such as private keys and authorization tokens from being committed at the source. What is the best approach to achieve this?
A healthcare organization recently suffered a security breach due to an exposed SSH key in one of its public Git repositories. To prevent similar incidents, the DevSecOps team decides to enforce a security mechanism that blocks sensitive information such as private keys and authorization tokens from being committed at the source. What is the best approach to achieve this?
정답: C
설명: (KoreaDumps 회원만 볼 수 있음)
문제4
Sarah Wright has recently joined a multinational company as a DevSecOps engineer. She has created a container and deployed a web application in it. Sarah would like to stop this container.
Which of the following commands stop the running container created by Sarah Wright?
Sarah Wright has recently joined a multinational company as a DevSecOps engineer. She has created a container and deployed a web application in it. Sarah would like to stop this container.
Which of the following commands stop the running container created by Sarah Wright?
정답: B
설명: (KoreaDumps 회원만 볼 수 있음)
문제5
Liam, a DevOps engineer at a fintech company, is responsible for managing a GKE-based application that handles sensitive customer data. During a security audit, the team identified unauthorized container images being deployed to the production environment. To address this, Liam must ensure that only container images built and signed through the company's Cloud Build pipeline are allowed for deployment. The solution must enforce deploy-time constraints and prevent any unauthorized images from being deployed to the GKE cluster. Which solution should Liam implement to enforce strict deploy-time constraints and ensure that only signed container images from the Cloud Build pipeline are deployed to the GKE cluster?
Liam, a DevOps engineer at a fintech company, is responsible for managing a GKE-based application that handles sensitive customer data. During a security audit, the team identified unauthorized container images being deployed to the production environment. To address this, Liam must ensure that only container images built and signed through the company's Cloud Build pipeline are allowed for deployment. The solution must enforce deploy-time constraints and prevent any unauthorized images from being deployed to the GKE cluster. Which solution should Liam implement to enforce strict deploy-time constraints and ensure that only signed container images from the Cloud Build pipeline are deployed to the GKE cluster?
정답: C
설명: (KoreaDumps 회원만 볼 수 있음)
문제6
Daniel, a DevSecOps engineer, is responsible for tracking and managing security risks and vulnerabilities in his organization's applications. To ensure an efficient workflow, he uses Jira to create security issues whenever a risk or vulnerability is detected. When a critical vulnerability is identified in the application, Daniel needs to determine whether the issue should follow a fix path, where the development team patches the code and revalidates it, or an accept risk path, where the issue is reviewed and deemed non-severe enough to proceed without a fix. Which approach should Daniel take if the vulnerability is critical and needs to be resolved before deployment?
Daniel, a DevSecOps engineer, is responsible for tracking and managing security risks and vulnerabilities in his organization's applications. To ensure an efficient workflow, he uses Jira to create security issues whenever a risk or vulnerability is detected. When a critical vulnerability is identified in the application, Daniel needs to determine whether the issue should follow a fix path, where the development team patches the code and revalidates it, or an accept risk path, where the issue is reviewed and deemed non-severe enough to proceed without a fix. Which approach should Daniel take if the vulnerability is critical and needs to be resolved before deployment?
정답: D
설명: (KoreaDumps 회원만 볼 수 있음)
문제7
Sophia, a DevSecOps engineer, is working on improving the security posture of her organization's cloud-native applications. She wants to integrate continuous threat modeling directly into the software development process to ensure that developers can identify security risks while writing code. To achieve this, she introduces a tool that allows developers to annotate source code with security concerns, generate data flow diagrams (DFDs), and create threat model reports dynamically. This approach enables real-time visibility into security risks and bridges the gap between development and security teams. Which tool should Sophia use to achieve this?
Sophia, a DevSecOps engineer, is working on improving the security posture of her organization's cloud-native applications. She wants to integrate continuous threat modeling directly into the software development process to ensure that developers can identify security risks while writing code. To achieve this, she introduces a tool that allows developers to annotate source code with security concerns, generate data flow diagrams (DFDs), and create threat model reports dynamically. This approach enables real-time visibility into security risks and bridges the gap between development and security teams. Which tool should Sophia use to achieve this?
정답: C
설명: (KoreaDumps 회원만 볼 수 있음)
문제8
Curtis Morgan is working as a DevSecOps engineer at Orchid Pvt. Ltd. His organization develops online teaching software. Beth McCarthy is working in a software development team, and she requested Curtis to help her in making pre-commit hooks executable on her local machine. Curtis went through the "repo.git\hooks" directory and removed the ".sample" extension from "pre- commit.sample" file by using "chmod +x filename" command and made the pre-commit hook executable on Beth's local machine. On the next day while developing the code for the software product, Beth accidentally committed the code with sensitive information. What will be the result of this commit?
Curtis Morgan is working as a DevSecOps engineer at Orchid Pvt. Ltd. His organization develops online teaching software. Beth McCarthy is working in a software development team, and she requested Curtis to help her in making pre-commit hooks executable on her local machine. Curtis went through the "repo.git\hooks" directory and removed the ".sample" extension from "pre- commit.sample" file by using "chmod +x filename" command and made the pre-commit hook executable on Beth's local machine. On the next day while developing the code for the software product, Beth accidentally committed the code with sensitive information. What will be the result of this commit?
정답: D
설명: (KoreaDumps 회원만 볼 수 있음)
문제9
Camila Duarte, a DevSecOps engineer at a Sao Paulo media company, is setting up her Jenkins pipeline to store database credentials, API keys, and TLS certificates outside of source code and configuration files, with automatic rotation and fine-grained access policies. Which type of tool should she integrate?
Camila Duarte, a DevSecOps engineer at a Sao Paulo media company, is setting up her Jenkins pipeline to store database credentials, API keys, and TLS certificates outside of source code and configuration files, with automatic rotation and fine-grained access policies. Which type of tool should she integrate?
정답: D
설명: (KoreaDumps 회원만 볼 수 있음)
문제10
A technology firm specializing in financial services has integrated Fortify Static Code Analyzer (SCA) with Jenkins to enforce secure coding practices within its CI/CD pipeline. The objective is to identify and remediate vulnerabilities early in the development lifecycle. After a recent build, the security team noticed that critical vulnerabilities were not flagged, despite Fortify SCA being executed within the pipeline. Jenkins logs confirmed that the scan completed successfully without any errors. However, when the security team manually executed Fortify SCA on the same codebase outside of Jenkins, multiple vulnerabilities were detected. Which of the following is the reason for the discrepancy in vulnerability detection?
A technology firm specializing in financial services has integrated Fortify Static Code Analyzer (SCA) with Jenkins to enforce secure coding practices within its CI/CD pipeline. The objective is to identify and remediate vulnerabilities early in the development lifecycle. After a recent build, the security team noticed that critical vulnerabilities were not flagged, despite Fortify SCA being executed within the pipeline. Jenkins logs confirmed that the scan completed successfully without any errors. However, when the security team manually executed Fortify SCA on the same codebase outside of Jenkins, multiple vulnerabilities were detected. Which of the following is the reason for the discrepancy in vulnerability detection?
정답: D
설명: (KoreaDumps 회원만 볼 수 있음)