Exit demo DEVSECOPS PeopleCert DevSecOps Exam PDF format · free preview

Peoplecert DEVSECOPS - Questions & Answers

Free preview · every answer includes a full explanation

Product page: https://prepkeys.com/devsecops.html

Question 1
Single choice

Which of the following BEST fills inthe bank?

"In DevSecOps environments information security is__________as much as possible into the daily work of development and operations".

A.

Designed

B.

Embedded

C.

integrated

D.

Automated

Question 2
Single choice

Which of the following BEST describes a public key cryptography architect?

A.

A person sends a message that is encrypted by using their private key, and the receiver must also use that private key to decipher the message.

B.

Messages are encrypted into cipher text and then are deciphered upon receipt by using a pair of public keys.

C.

Messages are encrypted into cipher text and then are deciphered upon receipt by using a pair of secure private keys.

D.

A person sends a message that is encrypted by the use of a public key, and the receiver can decipher the message using their private key.

Question 3
Single choice

Which of the following BEST describes a responsibility of a security champion?

A.

Testing

B.

inspiration

C.

Development

D.

Monitoring

Question 4
Single choice

When of the following BEST describes the type of data that requires both thesender and receiver to have encrypt/decrypt capacities?

A.

Data in database

B.

Data in local files

C.

Data in email message

D.

Data in memory card

Question 5
Single choice

Which of the following BEST describes automated security testing?

A.

Ensures that automated orchestration and provisioning software covers the scope of the application stack

B.

Ensures that continuous delivery pipelines integrate testing suites and capabilities into their toolchains

C.

Ensures that infrastructure and networks are software defined to enable rapid and reliable deployments

D.

Ensures that applications are developed to deliver the expected results and reveal any programming

errors early

Question 6
Single choice

Which of the following is BEST deserved as "being outside the scope of risk management inDevSecOps"?

A.

Manage major events that caused harm or loss

B.

inform business risk decisions for applications

C.

Assess me effectiveness of cybersecurity program

D.

Ensure the acuity to meet compliance controls

Question 7
Single choice

In shift-left thinking software Dogs and errors should IDEALLY be detected during which phase of testing?

A.

During UAT tests

B.

During staging tests

C.

During unit tests

D.

During system tests

Question 8
Single choice

Which of the following BEST describes an example of technical or design dew whendesigning for defensibility?

A.

Not prioritizing the set of critical customer feature in the current sprint

B.

Not including the addition of security controls in the definition of done

C.

Not developing comprehensive documentation and training material

D.

Not establishing all the product requirements prior to the first iteration

Question 9
Single choice

Which or the following BEST describes the proper order of the mainstages of continuous integration and the continuous delivery?

A.

Develop commit, build, lest provision release, and deploy

B.

Design, develop build test, provision deploy and release

C.

Develop commit, build test provision deploy and release

D.

Design develop build test provision release and deploy

Question 10
Single choice

When of the following BEST describes now the security principle of validation of a user's access and actions differ within a DevSecOps mindset versus a more traditional approach to this principle?

A.

The ad of validation is at the point of access

B.

The act of validation is at the point of request

C.

The act of validation is continuous and ongoing

D.

The act of validation focuses on credentials.

Showing 10 of 45 questions · Unlock the full set