312-97 Exam Question 11
Curtis Morgan has been working as a software developer in an MNC company. His team has developed a NodeJS application. While doing peer review of the NodeJS application, he observed that there are insecure libraries in the application. Therefore, he approached, Teresa Lisbon, who is working as a DevSecOps engineer, to detect the insecure libraries in the NodeJS application. Teresa used a SCA tool to find known vulnerabilities in JavaScript libraries for Node.JS applications and detected all the insecure libraries in the application. Which of the following tools did Teresa use for detecting insecure libraries in the NodeJS application?
312-97 Exam Question 12
Sarah Wheeler is an experienced DevSecOps engineer. She recently joined an IT company that develops software products for customers stretched across the globe. Sarah would like to use a security testing tool that protects the application from false positives, network sniffing, tampering with code, etc. The tool should monitor the incoming traffic to the server and APIs for suspicious activities and help her team in remediating them during runtime. Which of the following tools should Sarah select that will help her team in precisely detecting and remediating the security issues in the application code during runtime?
312-97 Exam Question 13
Dustin Hoffman is a DevSecOps engineer at SantSol Pvt. Ltd. His organization develops software products and web applications related to mobile apps. Using Gauntlt, Dustin would like to facilitate testing and communication between teams and create actionable tests that can be hooked in testing and deployment process. Which of the following commands should Dustin use to install Gauntlt?
312-97 Exam Question 14
Tobias Hartmann, a DevSecOps engineer at a Munich manufacturing firm, wants to simulate a full real-world attack chain - from initial reconnaissance through exploitation to lateral movement and data exfiltration - against a pre-production environment using both automated tools and skilled human testers, to validate defenses holistically. Which activity is Tobias planning?
312-97 Exam Question 15
Marcus Alberts, a DevSecOps engineer at a Berlin automotive supplier, must ensure that every artifact promoted from the Build stage to the Release stage is digitally signed, and that the deployment pipeline refuses to deploy any artifact whose signature cannot be verified. What security principle is Marcus enforcing?
