Ec-council | Learning
DevSecOps Certified EC-Cuncil Engineer (ECDE)

Master DevSecOps with ECDE certification: Learn how to design, secure and automate applications and infrastructures on site, AWS and Azure.
About EC-Council Certified DevSecOps Engineer Course
Course outline
Course outline:
Module 01 : Understanding DevOps Culture
Module 02 Introduction to DevSecOps
Module 03 : DevSecOps Pipeline - Planning Phase
Module 04 : DevSecOps Pipeline - Coding Phase
Module 05 : DevSecOps Pipeline - Construction and test phase
Module 06 : DevSecOps Pipeline - Release and Deployment Phase
Module 07 : DevSecOps Pipeline - Operation and Monitoring Phase
Description
- Information provided in course E|CDE are complemented by the practical implementation of laboratories that allow you to easily obtain a job of engineer DevSecOps in any part of the world.
- Whether your organization's workloads or applications are deployed in an on-site or cloud environment (AWS or Azure), this course will teach you how to use various DevSecOps tools and secure application code throughout the life cycle of software development.
- DevSecOps security tools that support the secure development of software products or web applications are subtly segmented into on-site and cloud environments.
- Course E|CDE not only focuses on DevSecOps application, but also provides insights into DevSecOps infrastructure.
- The integration of all popular and important tools is illustrated in the different stages of the DevOps life cycle.
- Programme E|CDE helps DevSecOps engineers develop and improve their knowledge and skills to secure the application at all stages of DevOps.
- This makes this certification a reference to all other DevSecOps certification programs available on the market.
Objectives of the course
Programme description
The DevSecOps training program aims to provide a thorough understanding of DevOps culture, associated tools and technologies, and integration of security into the development cycle, continuous delivery, and infrastructure management.
DevOps culture and security integration +
- Understand DevOps culture and principles and become familiar with the comprehensive list of tools and technologies that enable DevOps methodologies to be adopted.
- Understanding security bottlenecks when implementing DevOps and learning about DevSecOps culture, philosophy, practices and tools to improve collaboration between development and operations teams.
- Transform the organization's security practices from a traditional approach to integrating security into continuous delivery workflows.
- Understand the DevSecOps tool chain and include security controls in the DevOps automated pipeline.
Secure development tools +
- Learn to integrate Eclipse, GitHub with Jenkins to build apps.
- Align various security practices such as collecting security requirements, threat modelling, safe code reviews with development workflow.
- Integrate Jira and Confluence to manage security requirements.
- Integrate threat modelling tools such as Threat Dragon, Threat Modeler and Threatspec.
- Learn how to integrate security plugins, scanners and software composition analysis tools (SCA) to detect and mitigate vulnerabilities during development.
- Adopt Shift-Left approach to safety, from prevention to identification.
- Integrate SonarLint with Eclipse, Visual Studio and IDE VS Code.
- Implement tools like JFrog Security IDE Plugin, Snyk ID and Codac.
Integration of security in IC/CD +
- Learn to use Jenkins to create a secure CI/CD pipeline.
- Understand and implement continuous security testing using SAST tools (Synk, SonarQube, Checkmarx), DAST (Stackhawk, OWASP ZAP Baseline Scan), IAST and SCA tools.
- Integrate RASP tools like Hdiv, Sqreen and Dynatrace to protect the application during execution with less false positives.
- Integrate automated security tests into a CI/CD pipeline with AWS services (Amazon CloudWatch, AWS CodeCommit, etc.).
- Implement penetration testing tools such as GitGraber and GitMiner to secure the CI/CD pipeline.
Automation and infrastructure security +
- Various automation tools and practices help automate development, security and operations, both in on-site and cloud environments.
- Integrate tools like Jenkins, Bamboo, TeamCity and Gradle.
- Conduct continuous vulnerability analyses with tools such as Nessus, SonarQube, SonarCloud, Amazon Macie and Probely.
- Learn how to use DevSecOps AWS and Azure tools to secure applications.
- Understand the infrastructure as a code (IaC) to provide and configure the infrastructure with Ansible, Puppet and Chef.
Monitoring and compliance +
- Audit everything: code pushes, pipelines, compliance, using tools such as Sumo Logic, Datadog, Splunk, ELK and Nagios.
- Use automated monitoring and alerting tools such as Splunk, Azure Monitor and Nagios.
- Integrate compliance tools as a Code (CaC) such as Cloud Custodian and DevSec to meet regulatory requirements.
- Scan and secure the infrastructure using container and image scanners (Trivy, Qualys) and security scanners (BridgeCrew, Checkov).
- Create a continuous feedback in the DevSecOps pipeline with email notifications in Jenkins and Microsoft Teams.
- Integrate warning tools like OpsGenie to improve the performance and security of operations.
Review
Title of examination: DevSecOps Engineer Certified by EC-Council (ECDE)
Review Code: 312-97 (EXAM ECC), 312-50 (VUE)
Number of questions: 100
Review Format: Multiple choice
Duration: 4 hours
Availability: EC-Council Review Portal
Passing score: 70 %
Roles
- DevSecOps Engineer / DevSecOps Senior Engineer
- DevSecOps Cloud Engineer
- DevSecOps Azure Engineer
- DevSecOps AWS Engineer
- DevSecOps Analyst
- DevSecOps Specialist
- DevSecOps Operations Engineer
- DevSecOps System Administrator
- DevSecOps System Engineer
- Consultant DevSecOps
- DevSecOps Systems Engineer
- Engineer CI/CD DevSecOps
- DevSecOps Infrastructure Engineer


