
GitLabCertified Fundamentals Associate
Domain 5Objective 2
Interpret Security Scan Results GITLAB-CERTIFIED-GIT-ASSOCIATE Practice Questions (Page 2)
Part of the Security Scanning Basics domain, which makes up ~13% of our current practice bank.
23questions here
5free pages
3concepts
Questions 6–10
- 6
A security scan of a web application reports a vulnerability in a third-party component that is used across multiple applications. The vulnerability is rated high severity and could allow an attacker to execute arbitrary code. The team is responsible for maintaining the component. What is the most appropriate action?
Select an answer first - 7
When prioritizing security scan findings, which factor is most important to consider beyond the raw severity score?
Select an answer first - 8
A security scan reports a Cross-Site Scripting (XSS) vulnerability in a web application. Which remediation step is most directly aimed at fixing this issue?
Select an answer first - 9
A security scan identifies a high-severity vulnerability in a web application: a security misconfiguration in the server that exposes sensitive headers. The recommended remediation is to remove or mask the sensitive headers. What is the most effective way to implement this remediation?
Select an answer first - 10
A security scan of a web application reports a medium-severity vulnerability in a public-facing API that could allow an attacker to enumerate user accounts. The same scan also reports a low-severity vulnerability in an internal admin panel that could allow cross-site request forgery (CSRF). The company is about to launch a new feature that depends on the API. What is the best course of action?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GitLab. “GITLAB-CERTIFIED-GIT-ASSOCIATE” is a trademark of its owner, used for identification only.