ECCouncil EC-Council Certified DevSecOps Engineer (ECDE) - 312-97 FREE EXAM DUMPS QUESTIONS & ANSWERS
Sophia, a DevSecOps engineer, is working with her development team on a new feature rollout for a cloud-based application. As part of the DevSecOps workflow, she needs to ensure that security is integrated from the start. During the planning stage, she collaborates with security architects to understand the risk profile, compliance requirements, and security objectives of the new iteration. After identifying potential risks, Sophia works with the team to create data-flow diagrams (DFDs) to visualize how data moves across trust boundaries and analyze potential attack surfaces. Once threats are categorized, the team works on identifying mitigation strategies and validating countermeasures before finalizing the sprint. Which step of the DevSecOps threat modeling process is Sophia currently working on?
Correct Answer: C
Vote an answer
Explanation: Only visible for FreeCram members. You can sign-up / login (it's free).
Cindy Williams recently joined TechSecure Inc. as a DevSecOps engineer. She was assigned the task of improving the security of the company's Ruby-based applications within the CI/CD pipeline. To achieve this, she configured Bundler-Audit in Travis CI to scan for vulnerabilities in gem dependencies. After running the audit, Cindy discovered that some gems in the Gemfile.lock were outdated and contained security vulnerabilities. She quickly applied the necessary updates and ensured that the application used secure versions of the dependencies. Which method does Bundler-Audit use to identify security vulnerabilities in gem dependencies?
Correct Answer: B
Vote an answer
Explanation: Only visible for FreeCram members. You can sign-up / login (it's free).
Kenji Watanabe, a DevSecOps engineer at a Tokyo gaming studio, needs a testing tool that combines code instrumentation with live traffic analysis, so it can pinpoint the exact line of vulnerable code triggered when a QA tester clicks through the application during functional testing. Which approach should Kenji choose?
Correct Answer: D
Vote an answer
Explanation: Only visible for FreeCram members. You can sign-up / login (it's free).
Robin Tunney has been working as a DevSecOps engineer in an IT company located in Charleston, South Carolina. She would like to build a customized docker image using HashiCorp Packer. Therefore, she installed Packer and created a file docker-ubuntu.pkr.hcl; she then added HCL block to it and saved the file. Which of the following commands should Robin execute to build the Docker image using Packer?
Correct Answer: A
Vote an answer
Explanation: Only visible for FreeCram members. You can sign-up / login (it's free).
A multinational retail company is adopting AWS to modernize its software development lifecycle and improve automation, scalability, and deployment efficiency. The DevOps team is currently facing several challenges, including manual code compilation and testing, slow-release cycles, and frequent deployment errors that lead to application downtime. To address these issues, the company plans to integrate AWS DevOps services to optimize its CI/CD pipeline. The team needs a solution that can compile source code, run automated tests, and generate deployment-ready artifacts without requiring manual setup or server management. By implementing this solution, they aim to process multiple builds in parallel, improve test automation, and accelerate software delivery. Which AWS DevOps service should the company use to meet this requirement?
Correct Answer: A
Vote an answer
Explanation: Only visible for FreeCram members. You can sign-up / login (it's free).
A technology company recently implemented a continuous monitoring system to improve security, performance, and compliance across its cloud-based infrastructure and applications. The operations team set up monitoring tools to track infrastructure health, network stability, and application performance. After a routine system update, the company started experiencing intermittent service disruptions. Some users reported delayed responses, while others faced unexpected session timeouts. They investigated and reported that firewall settings and bandwidth usage, confirming that traffic flow remained stable. Analysis also shows that CPU, memory, and storage usage were within normal limits. Which aspect of continuous monitoring should the team investigate next?
Correct Answer: A
Vote an answer
Explanation: Only visible for FreeCram members. You can sign-up / login (it's free).
SoftPro Corp, a mid-sized software development company, embarked on its DevOps transformation journey to improve efficiency and streamline deployments. Initially, their development and operations teams worked in silos, causing slow deployments and frequent production issues. To enhance collaboration and automation, the company established cross-team collaboration to improve agility they implemented well-defined automated workflows to standardize deployments. At which DevOps Maturity Model stage is SoftPro Corp currently?
Correct Answer: C
Vote an answer
Explanation: Only visible for FreeCram members. You can sign-up / login (it's free).