ECCouncil EC-Council Certified DevSecOps Engineer (ECDE) - 312-97 模擬練習
Cindy Williams has recently joined an IT company as a DevSecOps engineer. She configured Bundle-Audit in Travis CI. Cindy detected vulnerability in Gemfile dependencies and resolved it by adding some line of codes. How does Bundler scan Gemfile.lock for insecure versions of gems?
正解: C
解説: (PassTest メンバーにのみ表示されます)
Yuki Sato, a DevSecOps engineer at a Yokohama consumer electronics company, discovers during a post-incident review that an attacker exploited a vulnerability that had actually been flagged by a scanner three months earlier but was never triaged or assigned an owner. Which process gap most directly caused this outcome?
正解: A
解説: (PassTest メンバーにのみ表示されます)
Viktor Petrov, a DevSecOps engineer at a Sofia energy company, discovers that a critical zero- day vulnerability has been disclosed in a widely used logging library that his organization's applications depend on. He needs to quickly identify every application and service across the company using that specific library and version. Which artifact/practice enables Viktor to do this quickly?
正解: B
解説: (PassTest メンバーにのみ表示されます)
Steven Gerrard has been working as a DevSecOps engineer at an IT company that develops software products and applications related to the healthcare industry. His organization has been using Azure DevOps services to securely and quickly develop software products. To ensure that the deployed infrastructure is in accordance with the architecture and industrial standards and the security policies are appropriately implemented, she would like to integrate InSpec with Azure.
Therefore, after installation and configuration of InSpec, she created InSpec profile file and upgraded it with personal metadata and Azure resource pack information; then she wrote the InSpec tests. Which of the following commands should Steven use to run InSpec tests to check the compliance of Azure infrastructure?
Therefore, after installation and configuration of InSpec, she created InSpec profile file and upgraded it with personal metadata and Azure resource pack information; then she wrote the InSpec tests. Which of the following commands should Steven use to run InSpec tests to check the compliance of Azure infrastructure?
正解: D
解説: (PassTest メンバーにのみ表示されます)
George Lennon is working as at InfoWorld Pvt. Solution as a DevSecOps engineer. His colleague, Sarah Mitchell, is a senior software developer. George told her to participate in a bug bounty program conducted by AWS for python and Java code developers. He informed Sarah that the challenge is a fun-based solution for bashing bugs, encouraging team building, and bringing friendly competition to enhance the quality of the code and application performance.
Acting on George's advice, Sarah participated in the bug bounty program and scored the highest points in the challenge, and she received a reward of $10,000. Based on the given information, which of the following bug bounty programs did Sarah participate?
Acting on George's advice, Sarah participated in the bug bounty program and scored the highest points in the challenge, and she received a reward of $10,000. Based on the given information, which of the following bug bounty programs did Sarah participate?
正解: B
解説: (PassTest メンバーにのみ表示されます)
William McDougall has been working as a DevSecOps engineer in an IT company located in Sacramento, California. His organization has been using Microsoft Azure DevOps service to develop software products securely and quickly. To take proactive decisions related to security issues and to reduce the overall security risk, William would like to integrate ThreatModeler with Azure Pipelines. How can ThreatModeler be integrated with Azure Pipelines and made a part of William's organization DevSecOps pipeline?
正解: D
解説: (PassTest メンバーにのみ表示されます)
Rafael Costa, a DevSecOps engineer at a Rio de Janeiro streaming company, wants to gradually enable a new recommendation algorithm for a subset of internal employees before opening it to all users, and needs the ability to instantly disable it without redeploying code if issues arise.
Which technique should Rafael use?
Which technique should Rafael use?
正解: D
解説: (PassTest メンバーにのみ表示されます)
Bruno Nascimento, a DevSecOps engineer at a Sao Paulo bank, wants to ensure that microservices communicating within his Kubernetes cluster mutually authenticate each other and encrypt all traffic between them, without modifying application code. Which technology should Bruno deploy?
正解: C
解説: (PassTest メンバーにのみ表示されます)