312-97 Sample Questions & Answers
Static and dynamic security testing at the build and test stage carries the most weight, bookended by DevOps culture, pipeline architecture, threat modeling and secret management early on, and runtime protection, IaC security, and monitoring later.
Launch the full 312-97 simulator →Showing 6 of 12 free samples.
- Question 1IntermediateSelect 2
Understanding DevOps Culture · AWS Cloud-Native DevOps
An organization is migrating its on-premises CI/CD pipeline to a fully cloud-native architecture on AWS. They need to replace their self-hosted Jenkins server and local Git repositories with managed AWS services. Which TWO of the following AWS services should the architect select to achieve this? (Select TWO)
Show answer & explanation
Correct answers: A, C
AWS CodeCommit is a managed source control service that hosts secure Git-based repositories, serving as a direct replacement for local Git servers.
AWS CodePipeline is a fully managed continuous delivery service that automates release pipelines, serving as a cloud-native replacement for orchestration tools like Jenkins.
- Question 2Advanced
Understanding DevOps Culture · Identifying Security Silos
A large healthcare provider is attempting to modernize its software delivery by adopting DevOps. Currently, they operate in strict silos: Developers write code and throw it over the wall to QA, who tests it manually for 3 weeks. Once approved, it is handed to the Security team, who performs a 2-week audit. Finally, Operations schedules a deployment window over a weekend.
The CIO wants to reduce the lead time from 6 weeks to 2 days. The Security Director is highly resistant, claiming that faster releases will inherently compromise HIPAA compliance and increase the risk of data breaches. The Operations Manager is concerned about deployment failures causing downtime.
As the lead DevSecOps architect, you must propose an initial strategy that addresses the cultural resistance while technically enabling the CIO's goal. Which approach represents the BEST initial step to break down these silos and accelerate the pipeline without sacrificing security?
flowchart LR Dev[Development] -->|Code Handoff| QA[QA Manual Testing] QA -->|Approval| Sec[Security Audit] Sec -->|Sign-off| Ops[Ops Deployment] style Dev fill:#f9f,stroke:#333,stroke-width:2px style QA fill:#ff9,stroke:#333,stroke-width:2px style Sec fill:#f96,stroke:#333,stroke-width:2px style Ops fill:#9cf,stroke:#333,stroke-width:2pxShow answer & explanation
Correct answer: B
The most effective way to break down silos and overcome cultural resistance is to create cross-functional teams where all stakeholders collaborate on the solution. By involving Security and Ops in building the automated pipeline and shifting security left (SAST/SCA), the organization can accelerate delivery while actually improving security and stability, addressing the concerns of both the Security Director and Operations Manager.
- Question 3Beginner
Introduction to DevSecOps · DevSecOps Principles and Philosophy
The principle of "Shift-Left" is foundational to DevSecOps. Which of the following best defines this concept?
Show answer & explanation
Correct answer: B
Shift-left refers to moving security considerations, testing, and validations earlier (to the "left") in the software development lifecycle (SDLC). Instead of waiting until the release or deployment stage to test for vulnerabilities, shift-left incorporates threat modeling during planning, SAST during coding, and automated testing during the build phase.
- Question 4Intermediate
Introduction to DevSecOps · Process Security Bottlenecks and Challenges
A software engineering team has fully automated their CI/CD pipeline, but deployments are still delayed by days because the security team mandates a manual review of all SAST and DAST reports before granting production access. What is the most effective DevSecOps strategy to overcome this process bottleneck?
Show answer & explanation
Correct answer: B
To resolve manual review bottlenecks, organizations should implement automated quality gates using Security Policy as Code. By defining acceptable risk thresholds (e.g., zero critical/high vulnerabilities), the pipeline can automatically evaluate the SAST/DAST results. Builds that meet the criteria proceed automatically, while only those that fail require manual intervention.
- Question 5Advanced
Introduction to DevSecOps · AI-Powered Security Tools
As DevSecOps matures, organizations are increasingly integrating Artificial Intelligence into their toolchains. Which of the following scenarios represents the most impactful use case for AI-driven SAST tools in a high-velocity CI/CD pipeline?
Show answer & explanation
Correct answer: B
Traditional SAST tools are notorious for generating high volumes of false positives, which causes alert fatigue and slows down high-velocity pipelines. AI-driven SAST uses machine learning to understand the context of the code, significantly reducing false positives, prioritizing true risks, and often providing automated remediation suggestions directly to developers.
- Question 6IntermediateSelect 3
Introduction to DevSecOps · Eight Stages of the DevOps Lifecycle
The DevOps lifecycle is generally categorized into eight distinct stages. Which THREE of the following are recognized stages in this standard pipeline architecture? (Select THREE)
Show answer & explanation
Correct answers: A, C, E
The eight stages of the DevOps lifecycle are Plan, Code, Build, Test, Release, Deploy, Operate, and Monitor. 'Plan' is the initial stage.
The eight stages of the DevOps lifecycle are Plan, Code, Build, Test, Release, Deploy, Operate, and Monitor. 'Operate' involves managing the application in production.
The eight stages of the DevOps lifecycle are Plan, Code, Build, Test, Release, Deploy, Operate, and Monitor. 'Release' prepares the validated build for deployment.
Ready for the real thing?
The full 312-97 simulator has every exam-style question, timed mode, and instant scoring.