CDP Cheat Sheet 2026

The 30 highest-yield CDP facts, distilled from real exam questions. Print it, save it as a PDF, or study it here — free, no sign-up.

80 questions
90 min time limit
80.00% to pass
  1. At which stage of a CI/CD pipeline should vulnerability scanning ideally first be integrated? During code commit and pull request creation
  2. How does incident response improve security in DevSecOps? Ensures security breaches are identified, contained, and mitigated
  3. In the STRIDE threat model, what does the letter 'T' represent? Tampering
  4. What is the primary purpose of a runbook in incident response? To provide step-by-step procedures for handling specific incident types
  5. How does continuing education relate to incident response & disaster recovery for CDP certified professionals? It ensures professionals stay current with evolving standards and best practices
  6. Which practice helps developers find and fix security issues before code is merged? Security-focused code review (peer review)
  7. When implementing incident response & disaster recovery practices, what should a CDP professional prioritize first? Compliance with established standards and protocols
  8. Container image signing and verification using tools like Cosign or Notary helps ensure: Only trusted, unmodified images are deployed in the cluster
  9. Under HIPAA Security Rule, which safeguard category addresses workstation use policies and physical access to servers? Physical safeguards
  10. Why is automation important in DevSecOps? Reduces manual errors and accelerates the development process
  11. What is a 'container image vulnerability scan' designed to detect? Known CVEs in OS packages and libraries bundled in a container image
  12. What is 'threat modeling' in the context of DevSecOps? Systematically identifying potential threats and mitigations during design
  13. What is the scoring range for CVSS (Common Vulnerability Scoring System) base scores? 0.0 to 10.0
  14. Which quality improvement method is most applicable to security architecture & network defense in Certified DevSecOps Professional? Plan-Do-Check-Act (PDCA) continuous improvement cycle
  15. A Kubernetes PodSecurityContext setting `readOnlyRootFilesystem: true` helps security by: Stopping attackers from writing malicious files to the container filesystem
  16. What is a common challenge professionals face when applying incident response & disaster recovery principles in Certified DevSecOps Professional? Balancing theoretical knowledge with practical application
  17. In a risk register, what does 'residual risk' represent? Risk that remains after controls have been applied
  18. What is a common risk of using overly broad IAM roles for CI/CD pipeline service accounts? A compromised pipeline can access and modify unintended cloud resources
  19. What does 'shift-left' security mean in the context of DevSecOps? Integrating security testing and practices earlier in the software development lifecycle
  20. Why is vulnerability management crucial in DevSecOps? Reduces the likelihood of exploitation by attackers
  21. How should a CDP professional handle a situation where cloud infrastructure & deployment protocols conflict with practical constraints? Document the conflict and seek guidance from appropriate authorities
  22. What is the National Vulnerability Database (NVD) primarily used for in vulnerability management? Enriching CVE records with CVSS severity scores and additional metadata
  23. Which tool category performs Static Application Security Testing (SAST)? Source code analyzers
  24. What is security automation in DevSecOps? Using tools and scripts to automatically perform security tasks
  25. Which metric measures how long an attacker remains in an environment before detection, directly reflecting monitoring program gaps? Dwell time (Mean Time to Detect)
  26. Which anomaly detection technique is best suited for detecting insider threats in a DevSecOps environment? User and Entity Behavior Analytics (UEBA)
  27. In DevSecOps, what does a 'risk appetite statement' formally define? The level and type of risk an organization is willing to accept in pursuit of objectives
  28. Which technology trend is most likely to impact cloud infrastructure & deployment in the CDP field in coming years? Digital tools for enhanced data collection, analysis, and reporting
  29. What is a common challenge professionals face when applying automation & scripting fundamentals principles in Certified DevSecOps Professional? Balancing theoretical knowledge with practical application
  30. Which attack technique involves exploiting a vulnerability inside a container to gain access to the host operating system? Container escape
Turn these facts into recall:
Was this helpful?