
GitLabCertified Fundamentals Associate
Domain 5Objective 2
Interpret Security Scan Results GITLAB-CERTIFIED-GIT-ASSOCIATE Practice Questions (Page 1)
Part of the Security Scanning Basics domain, which makes up ~13% of our current practice bank.
23questions here
5free pages
3concepts
Questions 1–5
- 1
When interpreting a security scan report, which piece of information is most directly used to identify the specific weakness that was detected?
Select an answer first - 2
A security scan of a web application reports a critical-severity vulnerability in a public-facing login page that could allow SQL injection. The same scan reports a high-severity vulnerability in an internal API that could allow unauthorized data access. The team has a release scheduled in two days. What is the best course of action?
Select an answer first - 3
A security scan of a web application reports a vulnerability in a dependency that is no longer maintained. The vulnerability is rated high severity and could allow remote code execution. The application is currently in production. What is the most appropriate action?
Select an answer first - 4
A security scan identifies a known vulnerability in a third-party library used by a project. What is the most common remediation step for this type of finding?
Select an answer first - 5
A developer receives a security scan report for a web application. The report lists a critical-severity SQL injection in a login endpoint, a high-severity cross-site scripting (XSS) issue in a search feature, and a medium-severity information disclosure in an error page. The team has limited capacity this sprint. Which finding should the team address first?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GitLab. “GITLAB-CERTIFIED-GIT-ASSOCIATE” is a trademark of its owner, used for identification only.