最新的ECCouncil EC-Council Certified DevSecOps Engineer (ECDE) - 312-97免費考試真題
問題1
Matt LeBlanc has been working as a DevSecOps engineer in an IT company that develops software products and web applications for IoT devices. His team leader has asked him to use GitRob tool to find sensitive data in the organizational public GitHub repository. To install GitRob, Matt ensured that he has correctly configured Go >= 1.8 environment and that $GOPATH/bin is in his $PATH. The GitHub repository URL from which he is supposed to install the tool is
https://github.com/michenriksen/gitrob. Which of the following command should Matt use to install GitRob?
https://github.com/michenriksen/gitrob. Which of the following command should Matt use to install GitRob?
正確答案: C
說明:(僅 VCESoft 成員可見)
問題2
Attackers exploited a vulnerability in a healthcare organization's application, injected malicious commands into user input fields, gained unauthorized access to the underlying server, exfiltrated patient records, and tampered with critical files. In this case, which of the following tools can assist the DevSecOps engineer of the organization in flagging the injection vulnerability in the codebase and provide actionable recommendations to fix the issue in their Azure DevOps pipeline?
正確答案: A
說明:(僅 VCESoft 成員可見)
問題3
Michael Johnson, a DevSecOps lead at a software development company, wants to ensure that security policies remain intact during the software deployment phase. His team has observed that manual security checks are prone to errors and inefficiencies, leading to misconfigurations and policy deviations. To address this, they seek an AI-powered solution that can manage security configurations, detect policy violations, and automate security testing within the development environment, ensuring a secure and compliant deployment process. Which of the following AI-powered technologies should Michael implement?
正確答案: A
說明:(僅 VCESoft 成員可見)
問題4
Sophia, a DevSecOps engineer, is working on a microservices-based application deployed using Docker containers. She recently debugged and manually configured a running container to fix a critical issue. Now, she wants to save these changes as a new Docker image so that the modified configuration can be reused without having to manually apply the same fixes in future deployments. Which of the following commands should Sophia use to capture the current state of the container as a new image?
正確答案: A
說明:(僅 VCESoft 成員可見)
問題5
Daniel Foster, a DevSecOps engineer at a software development company, is responsible for improving code quality and security in the development process. His team frequently encounters bugs and security vulnerabilities in the application code, which often require significant effort to fix after the code has already been committed. To address this, Daniel suggests integrating a tool that provides real-time feedback within the developer's environment, helping them identify and remediate security issues before committing code. This proactive approach ensures higher code quality and reduces security risks in later stages of development. Which of the following tools best aligns with Daniel's recommendation?
正確答案: A
說明:(僅 VCESoft 成員可見)
問題6
Curtis Morgan has been working as a software developer in an MNC company. His team has developed a NodeJS application. While doing peer review of the NodeJS application, he observed that there are insecure libraries in the application. Therefore, he approached, Teresa Lisbon, who is working as a DevSecOps engineer, to detect the insecure libraries in the NodeJS application. Teresa used a SCA tool to find known vulnerabilities in JavaScript libraries for Node.JS applications and detected all the insecure libraries in the application. Which of the following tools did Teresa use for detecting insecure libraries in the NodeJS application?
正確答案: D
說明:(僅 VCESoft 成員可見)

