InterviewSolution
This section includes InterviewSolutions, each offering curated multiple-choice questions to sharpen your knowledge and support exam preparation. Choose a topic below to get started.
| 1. |
Dynamic testing can be performed on the principles of white and black box testing. |
|
Answer» Dynamic testing can be performed on the principles of WHITE and black box testing. |
|
| 2. |
____________ tool is used to identify any accidental leakage of security keys by performing high entropy checks on the Git commit history. |
|
Answer» ____________ TOOL is used to identify any accidental leakage of security keys by performing high entropy CHECKS on the Git COMMIT history. |
|
| 3. |
Which of the following is the ideology to integrate security practices into the DevOps system? |
|
Answer» Which of the following is the ideology to INTEGRATE security practices into the DEVOPS system? |
|
| 4. |
How many components are there in the DevSecOps strategy? |
|
Answer» How many components are there in the DevSecOps strategy? |
|
| 5. |
_________ means specifying the criteria for enforcement in a language that can be read by humans and machines. Configurations can then be deployed, te |
|
Answer» _________ means specifying the criteria for enforcement in a language that can be READ by humans and machines. Configurations can then be deployed, tested, monitored, and REPORTED automatically throughout. |
|
| 6. |
__________ of the application is the act of configuring an application securely, updating it, creating rules and policies to help govern the applicati |
|
Answer» __________ of the application is the ACT of configuring an application SECURELY, updating it, creating rules and policies to help GOVERN the application in a secure manner, and removing unnecessary applications and services. |
|
| 7. |
How many phases are there in the Secure Software Development Life Cycle? |
|
Answer» How many PHASES are there in the Secure Software Development Life Cycle? |
|
| 8. |
________ is an operational framework that stimulates software consistency and standardization through automation while emphasizing collaboration betwe |
|
Answer» ________ is an operational FRAMEWORK that stimulates software consistency and standardization through automation while emphasizing collaboration between an ORGANIZATION's operations, development, testing, and SUPPORT teams. |
|
| 9. |
Which of the following can be defined as a family of activities for enhancing security by identifying objectives and vulnerabilities |
|
Answer» Which of the following can be defined as a family of activities for enhancing SECURITY by identifying objectives and vulnerabilities |
|
| 10. |
__________ tool is designed to identify common security problems in Python Code. |
|
Answer» __________ TOOL is designed to IDENTIFY common security problems in Python Code. |
|
| 11. |
Static code analysis is performed before the ________ begins. |
|
Answer» Static code ANALYSIS is PERFORMED before the ________ begins. |
|
| 12. |
FindBugs is used to find security vulnerabilities in __________ code. |
|
Answer» FINDBUGS is USED to find security vulnerabilities in __________ code. Choose the correct option from below LIST (1)C (2)Python (3)Java Answer:-(3)Java |
|
| 13. |
__________ is a structure in which organizations describe the mechanism used to create an application from its inception to its decommissioning. |
|
Answer» __________ is a STRUCTURE in which ORGANIZATIONS describe the MECHANISM used to CREATE an application from its inception to its decommissioning. |
|
| 14. |
_________ is a journey towards a frequent and more reliable release pipeline, automation, and stronger collaboration between development, IT, and busi |
|
Answer» _________ is a journey towards a frequent and more RELIABLE release pipeline, automation, and stronger COLLABORATION between DEVELOPMENT, IT, and business teams. |
|
| 15. |
Threat modeling comes under which phase of DevOps pipeline? |
|
Answer» Threat modeling COMES under which PHASE of DevOps pipeline? |
|
| 16. |
SonarQube, Checkmarx, FindBugs, and Fortify comes under which Software Composition Application tool? |
|
Answer» SonarQube, Checkmarx, FindBugs, and Fortify comes under which SOFTWARE Composition Application TOOL? |
|
| 17. |
Software Composition Application tools can be classified as Static Analysis Software Testing (SAST) tools and Dynamic Application Software Testing (DA |
|
Answer» SOFTWARE Composition APPLICATION tools can be classified as Static Analysis Software TESTING (SAST) tools and Dynamic Application Software Testing (DAST) tools. Choose the correct option from below list (1)True (2)False Answer:-(1)True |
|
| 18. |
Which of the following is/are the key benefit(s) of DAST? |
|
Answer» Which of the following is are the KEY benefit(s) of DAST? |
|