EC-Council · ECDE
EC-Council's current DevSecOps credential, exam 312-97, covering culture and secure practices across planning, coding, build and test, release and deployment, and operations and monitoring.
Practice Questions
609
≈ 4 practice exams
Duration
240 minutes
Passing Score
70%
Difficulty
AssociateLast Updated
Oct 2026
ECDE v2 follows a delivery pipeline instead of treating DevSecOps as a loose collection of tools. DevOps Culture contributes 10% and Introduction to DevSecOps 15%; the remaining 75% is divided evenly across planning, coding, build and test, release and deployment, and operation and monitoring. The current version adds Google Cloud and AI-assisted security work alongside on-premises, AWS, and Azure coverage.
Exam 312-97 contains 100 multiple-choice questions, allows four hours, and has a fixed 70% passing score. Candidates qualify through approved EC-Council training or a direct route requiring two years of information-security experience, a $100 eligibility application, and approval. The current exam voucher is listed at $550.
Use this 609-question bank to follow controls through the pipeline rather than memorizing product names. Start with 30 free questions, then spend three quarters of your practice on the five pipeline modules to mirror the official blueprint while keeping the two foundation modules in rotation.
EC-Council Certified DevSecOps Engineer (ECDE) v2 follows a delivery pipeline rather than treating security tools as disconnected topics. After foundations in DevOps culture and DevSecOps, 75% of the exam is divided evenly across planning, coding, build and test, release and deployment, and operation and monitoring.
The current v2 program expands coverage across on-premises environments, AWS, Azure, and Google Cloud, adds AI-assisted security work, and advertises more than 100 hands-on labs. The exam code remains 312-97.
EC-Council lists application-security professionals, DevOps engineers, software engineers and testers, IT-security professionals, cybersecurity engineers and analysts, and people with prior application-security knowledge among the intended audience.
The scope is end to end: threat modeling and secret management, secure coding and review, SCA and automated testing, infrastructure and containers, deployment controls, monitoring, incident response, availability, and recovery.
Candidates can qualify by completing approved official EC-Council training or through the direct route. Direct candidates need two years of verifiable information-security work experience, a completed eligibility application, a non-refundable $100 application fee, and formal approval.
The current brochure states that candidates should understand application-security concepts. It does not publish Docker, Kubernetes, a cloud platform, or a scripting language as separate mandatory prerequisites.
Exam 312-97 contains 100 multiple-choice questions, allows four hours, and has a published 70% passing score. EC-Council delivers it online through its exam portal.
The certification site currently lists an ECC exam voucher at $550. The separate v2 courseware-and-labs product is listed at $749 and does not include the exam voucher; training-partner prices can vary. A released voucher code is valid for one year.
ECDE v2 validates current DevSecOps knowledge across all eight DevOps stages represented by the seven-module exam blueprint. Its practical relevance is strongest for practitioners responsible for building security into delivery pipelines across code, infrastructure, cloud, deployment, and operations.
The credential runs on a three-year continuing-education cycle. Holders must earn 120 ECE/CPE credits during that cycle and pay the current $80 annual continuing-education fee, totaling $240 across three years.
5 sample questions with answers and explanations. The full bank has 609 questions, enough for 4 full-length practice exams.
Preview — answers shown1. An organization implements Docker container security and needs to ensure containers run with minimal privileges and cannot escalate privileges. Which three Docker security flags should they configure when running containers? (Select three!)
Multiple correct answersExplanation
The no-new-privileges security option prevents privilege escalation, cap-drop=ALL removes all Linux capabilities, and user 1000:1000 runs the container as a non-root user. These three flags work together to enforce least privilege. The privileged flag grants excessive permissions and contradicts security hardening. The cap-add=SYS_ADMIN adds administrative capabilities that should be avoided. While read-only filesystem is a good security practice, it is not specifically related to preventing privilege escalation.
2. A financial institution implements Kubernetes SecurityContext to enforce Pod Security Standards at the restricted level. Which three security settings must be configured in the Pod securityContext and container securityContext? (Select three!)
Multiple correct answersExplanation
Restricted Pod Security Standard requires running as non-root user, preventing privilege escalation, and using read-only root filesystem. These settings enforce the principle of least privilege. Running as user 0 (root) violates non-root requirements. Privileged mode grants excessive container permissions. HostNetwork allows access to the host network namespace, violating isolation principles.
3. An enterprise implements Docker Bench for Security to audit container host configurations against CIS Docker Benchmark. The security team wants to run only Section 2 checks covering Docker daemon configuration. Which command accomplishes this? (Select one!)
Explanation
Docker Bench for Security uses the -c parameter with check prefix followed by section number to run specific checks. The check_2 pattern runs all checks in Section 2 covering Docker daemon configuration. There is no --section parameter in Docker Bench. The --filter parameter does not exist for section filtering. The --cis-section parameter is not a valid Docker Bench option.
4. A company implements GCP Cloud Armor security policies for their global load balancer. The security team needs to block requests matching OWASP ModSecurity Core Rule Set for cross-site scripting. Which preconfigured expression should be used in the security policy rule? (Select one!)
Explanation
Cloud Armor uses evaluatePreconfiguredExpr function with preconfigured rule names like xss-stable for cross-site scripting detection based on OWASP ModSecurity Core Rule Set. The stable suffix indicates production-ready rules. The evaluateOWASPRule function does not exist in Cloud Armor. The preconfiguredWafRule function is not valid Cloud Armor syntax. The cloudArmorRule function and rule name format are incorrect.
5. An enterprise implements Snyk for software composition analysis in their Node.js application. The security policy requires blocking builds with any high-severity vulnerabilities and continuous monitoring for new vulnerabilities after deployment. Which two Snyk commands should be integrated? (Select two!)
Multiple correct answersExplanation
snyk test with --severity-threshold=high tests dependencies and fails the build if high or critical vulnerabilities are found, meeting the build blocking requirement. snyk monitor sends a snapshot to Snyk for continuous monitoring, alerting on new vulnerabilities in deployed dependencies. snyk container scan is for container images, not Node.js dependency scanning. snyk iac test scans infrastructure as code, not application dependencies. snyk code test performs SAST on source code, not dependency analysis.
The current program is EC-Council Certified DevSecOps Engineer (ECDE) v2. The certification exam code is 312-97.
ECDE has 100 multiple-choice questions, a four-hour time limit, and a fixed 70% passing score. EC-Council delivers it online through its exam portal.
Understanding DevOps Culture is 10%. Introduction to DevSecOps and each of the five pipeline-stage modules are 15% apiece.
Yes, but direct candidates need two years of verifiable information-security experience, a completed eligibility application, the $100 application fee, and formal approval.
EC-Council currently lists the ECC exam voucher at $550. The separate courseware-and-labs product is $749 and does not include the voucher; partner training prices vary.
Earn 120 ECE/CPE credits during the three-year cycle and pay the $80 annual continuing-education fee, totaling $240 across three years.
Certified Cloud Security Engineer (CCSE)
CCSE · 624 questions
Certified Network Defender (CND)
CND · 562 questions
Certified Cybersecurity Technician (CCT)
212-82 · 630 questions
Digital Forensics Essentials (DFE)
DFE · 626 questions
EC-Council Certified Disaster Recovery Professional (EDRP)
EDRP · 623 questions
Certified Application Security Engineer .NET (CASE-.NET)
CASE-.NET · 625 questions
$17.99
One-time access to this exam