312-97 Exam Question 1

Kenji Watanabe, a DevSecOps engineer at a Tokyo gaming studio, needs a testing tool that combines code instrumentation with live traffic analysis, so it can pinpoint the exact line of vulnerable code triggered when a QA tester clicks through the application during functional testing. Which approach should Kenji choose?
  • 312-97 Exam Question 2

    Allen Smith has been working as a senior DevSecOps engineer for the past 4 years in an IT company that develops software products and applications for retail companies. To detect common security issues in the source code, he would like to integrate Bandit SAST tool with Jenkins. Allen installed Bandit and created a Jenkins job. In the Source Code Management section, he provided repository URL, credentials, and the branch that he wants to analyze. As Bandit is installed on Jenkins' server, he selected Execute shell for the Build step and configure Bandit script. After successfully integrating Bandit SAST tool with Jenkins, in which of the following can Allen detect security issues?
  • 312-97 Exam Question 3

    Oliver Bennett, a DevSecOps engineer at a London insurance firm, discovers that a base container image his team relies on has an outdated OpenSSL package with a known critical CVE.
    He wants an automated scanner integrated into the Build stage to flag such OS-level package vulnerabilities in container images before they are pushed to the registry. Which tool category should Oliver use?
  • 312-97 Exam Question 4

    Lara Grice has been working as a DevSecOps engineer in an IT company located in Denver, Colorado. Her team leader has told her to save all the container images in the centos repository to centos-all.tar. Which of the following is a STDOUT command that Lara can use to save all the container images in the centos repository to centos-all.tar?
  • 312-97 Exam Question 5

    William Friedkin has been working as a DevSecOps engineer in an IT company for the past 3 years. His team leader has asked him to validate the host configuration that runs the Docker containers and perform security checks at the container level by implementing Docker's CIS Benchmark Recommendations. Therefore, William would like to integrate Docker Bench with Jenkins to incorporate security testing in DevOps workflow and secure the Docker Container.
    Before starting the procedure, he would like to install openssh on Ubuntu. Which of the following command should William run to install openssh on Ubuntu?