ECcouncil certification preparation
312-97 Practice Questions
Practice exam-style questions, check your answers, and review explanations and source references where they are available.
- Exam
- 312-97
- Provider
- ECcouncil
- Full set
- 100 questions
- Last Update Check
(Sandra Oliver joined SinClare Soft Pvt. Ltd. as a DevSecOps engineer in January of 2010. Her
organization develops software and web applications related to the healthcare industry. Using IAST
runtime security testing technology, she is detecting and diagnosing security issues in applications
and APIs. The IAST solution used by Sandra encompasses a web scanner with an agent that works
inside the server that hosts the application to provide additional analysis details such as the location
of the vulnerability in the application code. Based on the given information, which of the following
IAST solutions is Sandra using?)
Question 1 discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
(Robert Wheeler has been working as a DevSecOps engineer in an IT company for the past 5 years.
His organization develops software products and web applications related to AutoCAD. Rob would
like to integrate Rapid7 tCell Next-Gen Cloud WAF and RASP Tool with AWS CloudFront to protect
application by identifying suspicious actors, enforcing content security policies (CSPs), and securing
against unvalidated HTTP redirections on web applications. How can Rob deploy the tCell agent as a
CloudFormation stack into his organization AWS account?.)
Question 2 discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
(Debra Aniston is a DevSecOps engineer in an IT company that develops software products and web
applications. Her team has found various coding issues in the application code. Debra would like to
fix coding issues before they exist. She recommended a DevSecOps tool to the software developer
team that highlights bugs and security vulnerabilities with clear remediation guidance, which helps
in fixing security issues before the code is committed. Based on the information given, which of the
following tools has Debra recommended to the software development team?)
Question 3 discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
(Craig Kelly has been working as a software development team leader in an IT company over the past
8 years. His team is working on the development of an Android application product. Sandra Oliver, a
DevSecOps engineer, used DAST tools and fuzz testing to perform advanced checks on the Android
application product and detected critical and high severity issues. She provided the information
about the security issues and the recommendations to mitigate them to Craig’s team. Which type of
security checks performed by Sandra involve detection of critical and high severity issues using DAST
tools and fuzz testing?)
Question 4 discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
(Walter O’Brien recently joined as a junior DevSecOps engineer in an IT company located in Lansing,
Michigan. His organization develops robotic process automation software for various clients
stretched across the globe. Walter’s team leader asked him to configure username and user email for
git in VS Code. Therefore, he opened Visual Studio Code IDE console, then clicked on Terminal tab
and selected New terminal. Which of the following command should Walter execute in the terminal
to configure username and user email for git in VS Code?)
Question 5 discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
(SinCaire is a software development company that develops web applications for various clients. To
measure the successful implementation of DevSecOps, the organization enforced U.S. General
Service Administrator (GSA) high-value DevSecOps metrics. Which of the following metrics
implemented by SinCaire can measure the time between the code commit and production, and
tracks the bug fix and new features throughout the development, testing, and production phases?)
Question 6 discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
(William Scott, after completing his graduation in computer science, joined an IT company as a
DevSecOps engineer. His team leader has asked him to use GitHub Code Scanning for evaluating the
source code in his organization’s GitHub repository to detect security issues and coding errors. How
can William set up coding scanning in GitHub repository?)
Question 7 discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
(Charles Rettig has been working as a DevSecOps engineer in an IT company that develops software
and web applications for IoT devices. He integrated Burp Suite with Jenkins to detect vulnerabilities
and evaluate attack vectors compromising web applications. Which of the following features offered
by Burp Suite minimizes false positives and helps detect invisible vulnerabilities?)
Question 8 discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
(Dustin Hoffman has been working as a DevSecOps engineer in an IT company located in San Diego,
Californi
a. For detecting new security vulnerabilities at the beginning of the source code development, he
would like to integrate Checkmarx SCA tool with GitLab. The Checkmarx template has all the jobs
defined for pipeline. Where should Dustin incorporate the Checkmarx template file
‘https://raw.githubusercontent.com/checkmarx-ltd/cxflow/develop/templates/gitlab/v3/Checkmarx.gitlab-ci.yml’?)
Question 9 discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
(Jason Wylie has been working as a DevSecOps engineer in an IT company located in Sacramento,
Californi
a. He would like to use Jenkins for CI and Azure Pipelines for CD to deploy a Spring Boot app to an
Azure Container Service (AKS) Kubernetes cluster. He created a namespace for deploying the Jenkins
in AKS, and then deployed the Jenkins app to the Pod. Which of the following commands should
Jason run to see the pods that have been spun up and running?)
Question 10 discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Question 1 of 10
Source context
How this practice set is maintained
Maintained by the CertMage content team, this page loads questions from the exam dataset connected to its preparation resource. When an answer includes a supporting reference, it is shown with that answer so you can review the underlying vendor documentation.
Certification objectives, interfaces, and vendor services can change. Verify important details against the provider's current exam guide and documentation before your exam.
