(Alexander Hamilton has been working as a senior DevSecOps engineer in an IT company located in Greenville, South Carolina. In January of 2012, his organization because a victim of a cyber security attack and incurred a tremendous loss. Alexander's organization immediately adopted AWS cloud-based services after the attack to develop robust software products securely and quickly. To detect security issues in code review, Alexander would like to integrate SonarQube with AWS Pipeline; therefore, he created a pipeline in AWS using CloudFormation pipeline template. Then, he selected SonarQube tool from the tools dropdown, provided the required stack parameters, and also provided email address for receiving email notifications of changes in pipeline status and approvals. He deployed the pipeline after entering the required information.
What will happen when changes are committed in the application repository?.)
A. BinSkim event is created.
B. Security Hub event is created.
C. Cloud Config event is created.
D. CloudWatch event is created.
正解:D
解説: (Pass4Test メンバーにのみ表示されます)
質問 2:
(Gabriel Jarret has been working as a senior DevSecOps engineer in an IT company located in Houston, Texas. He is using Vault to manage secrets and protect sensitive data. On February 1, 2022, Gabriel wrote the secret using vault kv put secret/wejskt command. On February 10, 2022, his team detected a brute-force attack using Splunk monitoring tool. Gabriel would like to delete the secrets in the vault that he wrote on February 1, 2022. Which of the following commands should Gabriel use to delete a secret in Vault secret management tool?)
A. vault kv del secret/wejskt.
B. vault kv -delete secret/wejskt.
C. vault kv delete secret/wejskt.
D. vault kv -del secret/wejskt.
正解:A
解説: (Pass4Test メンバーにのみ表示されます)
質問 3:
(Jason Wylie has been working as a DevSecOps engineer in an IT company located in Sacramento, California. He would like to use Jenkins for CI and Azure Pipelines for CD to deploy a Spring Boot app to an Azure Container Service (AKS) Kubernetes cluster. He created a namespace for deploying the Jenkins in AKS, and then deployed the Jenkins app to the Pod. Which of the following commands should Jason run to see the pods that have been spun up and running?)
A. kubectl get pods -s jenkins.
B. kubectl get pods -n jenkins.
C. kubectl get pods -p jenkins.
D. kubectl get pods -k Jenkins.
正解:B
解説: (Pass4Test メンバーにのみ表示されます)
質問 4:
(Debra Aniston has recently joined an MNC company as a DevSecOps engineer. Her organization develops various types of software products and web applications. The DevSecOps team leader provided an application code and asked Debra to detect and mitigate security issues. Debra used w3af tool and detected cross-site scripting and SQL injection vulnerability in the source code. Based on this information, which category of security testing tools is represented by w3af?.)
A. SAST.
B. IAST.
C. SCA.
D. DAST.
正解:D
解説: (Pass4Test メンバーにのみ表示されます)
質問 5:
(Patricia Cornwell has been working as a DevSecOps engineer in an IT company that provides custom software solutions. She would like to use GitMiner to mine the secret credentials such as usernames and passwords, API credentials, and other sensitive data from GitHub. Therefore, to start the scanning, she cloned the repo to the local machine by using the git clonehttp://github.com/UnkL4b/GitMinercommand; then, she moved to the current directory using $ cd GitMiner command. Which of the following commands should Patricia use to install the dependencies?)
A. pip3 install -m requirement.txt.
B. pip3 install -d requirement.txt.
C. pip3 install -r requirement.txt.
D. pip3 install -q requirement.txt.
正解:C
解説: (Pass4Test メンバーにのみ表示されます)
質問 6:
(Elizabeth Moss has been working as a DevSecOps engineer in an IT company located in San Diego, California. Due to the robust security and cost-effective service provided by AWS, her organization transferred all the workloads from on-prem to AWS cloud in 2017. Elizabeth would like to prevent committing AWS keys into repositories; therefore, she created a global git-templates directory using command line. Then, she created another directory, named it as hooks, wherein she created a file named pre- commit. In the pre-commit file, Elizabeth pasted the script that would prevent committing AWS keys into the repositories. She would like to ensure that the hook is executable. Which of the following command should Elizabeth run to make sure that the pre-commit hook is executable?)
A. chmod a+e ~/.hooks/git-templates/pre-commit.
B. chmod a+x ~/.git-templates/hooks/pre-commit.
C. chmod a+x ~/.hooks/git-templates/pre-commit.
D. chmod a+e ~/.git-templates/hooks/pre-commit.
正解:B
解説: (Pass4Test メンバーにのみ表示されます)
1104 お客様のコメント





望月** -
合格出来ました。説明が非常に分かりやすく間違い選択肢についても確認できる,。ここで感謝を申し上げます。ありがとうございました。