312-97 Exam Question 36

Andrew Gerrard has recently joined an IT company that develops software products and applications as a DevSecOps engineer. His team leader asked him to download a jar application from the organization GitHub repository and run the BDD security framework. Andrew successfully downloaded the jar application from the repository and executed the jar application; then, he cloned the BDD security framework. Which of the following commands should Andrew use to execute the authentication feature?
  • 312-97 Exam Question 37

    Chidinma Eze, a DevSecOps engineer at a Lagos e-commerce company, needs to define measurable targets - such as "95% of critical vulnerabilities remediated within 7 days" - that her security and engineering teams are jointly accountable for meeting. What are these targets called?
  • 312-97 Exam Question 38

    Grace Odhiambo, a DevSecOps engineer at a Nairobi-based agritech firm, needs to scan her organization's Java-based application source code for insecure coding patterns such as SQL injection and hardcoded credentials without executing the application. Which category of testing should she use?
  • 312-97 Exam Question 39

    Christopher Brown has been working as a DevSecOps engineer in an IT company that develops software and web applications for an ecommerce company. To automatically detect common security issues and coding error in the C++ code, she performed code scanning using CodeQL in GitHub. Which of the following entries will Christopher find for CodeQL analysis of C++ code?
  • 312-97 Exam Question 40

    Richard Branson has been working as a DevSecOps engineer in an IT company that develops apps for Android mobiles. To manage the secret information of an application in various phases of development lifecycle and to provide fine-grained access to each secret, he would like to integrate HashiCorp Vault with Jenkins. To access the vault from Jenkins, Richard installed hashicorp-vault- plugin and ran a vault instance; he then selected the AppRole authentication method, which allows apps to access vault with a predefined role. Which of the following commands should Richard use to enable AppRole authentication?