EC-COUNCIL · 312-97

EC-Council 312-97 ECDE Exam Practice Questions

100 questionsPDF by emailUpdated September 2026

US$39

Try 10 questions free

Card, Apple Pay or Google Pay. Your PDF is sent by email as soon as you check out.

Pass or your money backFail the exam after using this pack and we refund it. How the guarantee works
Category:
TRY BEFORE YOU BUY

Three of the 100 questions in this pack

Question 1

Andrew Gerrard has recently joined an IT company located in Fairmont, California, as a DevSecOps engineer. Due to robust security and costeffective service provided by AWS, his organization has migrated all the workloads from on-prem to AWS cloud in January of 2020. Andrew’s team leader has asked him to integrate AWS Secret Manager with Jenkins. To do so, Andrew installed the “AWS Secret Manager Credentials provider” plugin in Jenkins and configured an IAM policy in AWS that allows Jenkins to take secrets from AWS Secret manager.

Which of the following file should Andrew edit to add access id and secret key parameters along with the region copied from AWS?

  1. /etc/filebeat/filebeat.yml
  2. /etc/sysconfig/Jenkins
  3. /etc/file/Jenkins
  4. /etc/sysconfig file/Jenkins
Show answer and explanation

Correct answer: B. /etc/sysconfig/Jenkins

When configuring Jenkins to authenticate with AWS services, credentials such as access key ID and secret key are typically stored in the Jenkins configuration file located at /etc/sysconfig/jenkins. This file contains environment variables and configuration parameters that Jenkins reads at startup, making it the appropriate location for AWS credential parameters and region configuration when integrating with AWS Secret Manager.

Why the other options are wrong

  • A. filebeat.yml is a configuration file for Filebeat (log shipping), not Jenkins AWS credentials.
  • C. /etc/file/Jenkins is not a valid Jenkins configuration path.
  • D. /etc/sysconfig file/Jenkins is not a valid file path syntax.

Question 2

Gabriel Bateman has been working as a DevSecOps engineer in an IT company that develops virtual classroom software for online teaching. He would like to clone the BDD security framework on his local machine using the following URL, https://github.com/continuumsecurity/bdd-security.git.

Which of the following command should Gabriel use to clone the BBD security framework?

  1. git clone https://github.com/continuumsecurity/bdd-security.git
  2. git clone https://github.com/continumsecurity/bdd-security.git
  3. github clone https://github.com/continumsecurity/bdd-security.git
  4. github clone https://github.com/continuumsecurity/bdd-security.git
Show answer and explanation

Correct answer: A. git clone https://github.com/continuumsecurity/bdd-security.git

security.git The correct git command to clone a repository is 'git clone' followed by the repository URL. Option A uses the correct command syntax 'git clone' with the proper GitHub URL containing the correct repository name 'bdd-security'. This is the standard Git command for cloning remote repositories to a local machine.

Why the other options are wrong

  • B. This option uses 'continumsecurity' instead of 'continuumsecurity', which is an incorrect GitHub organization name.
  • C. 'github clone' is not a valid Git command; the correct command is 'git clone'.
  • D. 'github clone' is not a valid Git command, and the organization name is also misspelled as 'continuumsecurity'.

Question 3

William Edwards is working as a DevSecOps engineer at SVR Software Solution Pvt. Ltd. His organization develops software products and applications related to digital marketing. William integrated Prisma Cloud with Jenkins to detect threat-intelligence based threat detection. This integration will allow him to scan container images and serverless functions for security issues in the CI/CD pipeline.

Which of the following is employed by Prisma Cloud to understand the normal network behavior of each customer’s cloud environment to detect network anomalies and zero- day attacks effectively with minimal false positives?

  1. Advanced unsupervised machine learning
  2. Advanced supervised data mining
  3. Advanced supervised machine learning
  4. Advanced unsupervised data mining
Show answer and explanation

Correct answer: A. Advanced unsupervised machine learning

Prisma Cloud employs advanced unsupervised machine learning to establish baseline patterns of normal network behavior specific to each customer's cloud environment. Unsupervised learning algorithms identify anomalies by detecting deviations from learned normal behavior patterns without requiring labeled training data, enabling effective detection of zero-day attacks and network anomalies with minimal false positives.

Why the other options are wrong

  • B. Supervised data mining requires labeled training data and is not the appropriate method for establishing baseline behavior patterns in dynamic cloud environments.
  • C. Supervised machine learning requires pre-labeled data and is not suitable for detecting unknown zero-day attacks and novel network anomalies.
  • D. Supervised data mining is not the correct approach; Prisma Cloud uses machine learning, not data mining, and it employs unsupervised rather than supervised techniques.

See all 10 free questions Get the full pack, US$39

100 practice questions for EC-Council Certified DevSecOps Engineer (ECDE), exam 312-97, with full explanations.

Every question comes with the correct answer, the reasoning behind it, and a short note on why each wrong option is wrong. Work through it once with the answers, then again with the questions-only copy under exam conditions.

  • 100 questions mapped to the ECDE exam blueprint
  • Answers and explanations for every question, including the wrong options
  • A questions-only PDF for timed practice runs
  • Instant delivery by email the moment you check out
  • Free monthly updates for as long as the exam is live
  • Pass or your money back

A 312-97 attempt costs US$550. This pack is US$39, paid once.

Try 10 questions free before you buy.

Last updated September 2026 · 100 questions

What makes the ECDE hard

ECDE is organised around the pipeline rather than around security topics. The blueprint walks the DevOps lifecycle stage by stage, plan, code, build and test, release and deploy, operate and monitor, and asks what security belongs at each stage and which tool does it, in both on-premises pipelines and AWS and Azure native tooling.

100 questions in four hours gives plenty of time, and most of the questions are scenarios about where in the pipeline a control should go.

Plan and code cover threat modelling and secure coding, with SAST and secret detection tools. Build and test cover software composition analysis, container image scanning, DAST, IAST and fuzzing. Release and deploy cover infrastructure as code security, container and Kubernetes orchestration security, and secrets management. Operate and monitor cover logging, runtime security, SIEM integration and continuous compliance. The passing score is 70%.

About the exam

312-97 (Certified DevSecOps Engineer) earns the EC-Council ECDE certification. It covers DevOps and DevSecOps culture and principles and the security of each pipeline stage: plan, code, build and test, release and deploy, and operate and monitor, on-premises and in AWS and Azure. There are no prerequisites with official training; self-study candidates need two years of experience and an eligibility application.

Exam modules

  • Understanding DevOps culture
  • Introduction to DevSecOps
  • DevSecOps pipeline: plan stage
  • DevSecOps pipeline: code stage
  • DevSecOps pipeline: build and test stage
  • DevSecOps pipeline: release and deploy stage
  • DevSecOps pipeline: operate and monitor stage

100 multiple choice questions, 240 minutes, passing score 70%, US$550 per attempt, ECC Exam Portal with remote proctoring, certification valid for three years with EC-Council continuing education.

Reviews

There are no reviews yet.

Only logged in customers who have purchased this product may leave a review.

Questions before you buy

What do I get when I buy the EC-Council 312-97 ECDE pack?

100 practice questions as a PDF, each with the correct answer, a full explanation and a note on why the other options are wrong, plus a separate questions-only PDF for timed practice.

How quickly do I receive it?

Your PDF is prepared and sent to your email address after checkout, and you get a confirmation as soon as it is on its way.

Is there a free sample?

Yes. Ten questions from this pack, with answers and explanations, are free on this page and as a PDF, so you can judge the quality before you pay.

Are updates included?

Yes. The pack is updated every month for as long as the exam is live, and updates are free for everyone who has bought it.

What if I fail the exam?

We refund the pack. Sit the exam 7 to 30 days after buying, then send your official score report within 7 days of the exam date, as set out in the refund policy.

Can I share it with colleagues?

Each purchase is licensed to one person. For a team, school or training organisation, email support@certstash.com for a licence that fits.