Skip to content

312-97 EC-Council Certified DevSecOps Engineer (ECDE) Practice Questions

Prepare for 312-97 with more than an answer.

159 questions in the full set12 sample questionsUpdated Mar 12, 2026
Exam fee
$550 USD
Time limit
240 minutes
Questions on the exam
100
Passing score
70%
Level
Professional
Valid for
3 years
Domains covered on the exam 7
  1. Understanding DevOps Culture10%
  2. Introduction to DevSecOps12%
  3. DevSecOps Pipeline - Plan Stage14%
  4. DevSecOps Pipeline - Code Stage16%
  5. DevSecOps Pipeline - Build and Test Stage20%
  6. DevSecOps Pipeline - Release and Deploy Stage18%
  7. DevSecOps Pipeline - Operate and Monitor Stage10%
  1. 1

    True or False: A 'Security Champion' is typically a senior member of the dedicated InfoSec team who is assigned to police the development team's activities and enforce strict compliance mandates.

    Show answer details

    Correct answer: B

    False. A Security Champion is usually a member of the development or engineering team (not the central InfoSec team) who takes on a voluntary or designated role to promote security best practices within their own team. They act as a bridge between security and development, advocating for security rather than acting as a policing force.

  2. 2

    The acronym for the security testing methodology that analyzes running applications from the inside, providing deep visibility into application execution, data flow, and memory to detect vulnerabilities is _____.

    Show answer details

    Correct answer: C

    IAST (Interactive Application Security Testing) works from within the application through instrumentation. Unlike SAST (which analyzes static code) or DAST (which attacks from the outside), IAST monitors the application's internal behavior during runtime or automated functional testing to identify vulnerabilities with high accuracy.

  3. 3

    During the Plan stage of the DevSecOps pipeline, an architect uses the STRIDE methodology to model threats against a new microservice. They identify a scenario where an attacker might alter the payload of a REST API request in transit. Which specific element of the STRIDE model does this scenario represent?

    Show answer details

    Correct answer: B

    In the STRIDE threat model, 'Tampering' refers to the malicious modification of data. Altering an API payload in transit is a classic tampering attack, which is typically mitigated by implementing integrity controls and transport layer security (TLS).

  4. 4

    A traditional financial institution is transitioning from a Waterfall SDLC to a DevOps methodology. The organization currently suffers from long release cycles and frequent deployment failures due to misaligned environments. Which of the following represents the most critical cultural shift the organization must achieve to successfully implement DevOps principles?

    Show answer details

    Correct answer: B

    The core of DevOps is a cultural transformation that breaks down silos between development and operations teams. While automation and cloud technologies are enablers, the fundamental requirement is adopting a shared responsibility model where both teams collaborate throughout the entire lifecycle. Without this cultural shift, merely adopting new tools will not resolve the underlying communication and alignment issues.

  5. 5

    When distinguishing between the core components of CI/CD, which statement accurately differentiates Continuous Delivery from Continuous Deployment?

    Show answer details

    Correct answer: B

    Continuous Delivery means the software is always in a deployable state, but the actual release to production is a manual business decision. Continuous Deployment takes this a step further by removing the manual gate, automatically deploying every change that passes the automated test suite directly to production.

  6. 6

    True or False: In a mature DevOps culture, the development team assumes sole responsibility for application functionality and code quality, while the operations team assumes sole responsibility for infrastructure uptime and scalability.

    Show answer details

    Correct answer: B

    False. A mature DevOps culture relies heavily on a model of 'shared responsibility'. Developers take ownership of how their code performs in production (including uptime considerations), and operations teams are involved earlier in the lifecycle to understand application architecture. Siloed responsibilities contradict DevOps principles.

Create an account to continue.