
GitLabCertified Fundamentals Associate
Domain 5Objective 2
Interpret Security Scan Results GITLAB-CERTIFIED-GIT-ASSOCIATE Practice Questions (Page 3)
Part of the Security Scanning Basics domain, which makes up ~13% of our current practice bank.
23questions here
5free pages
3concepts
Questions 11–15
- 11
A security scan identifies a high-severity vulnerability in a web application: a cross-site scripting (XSS) flaw in a search feature. The recommended remediation is to sanitize user input and encode output. What is the most effective way to implement this remediation?
Select an answer first - 12
A security scan identifies two vulnerabilities: one is a critical-severity issue in an internet-facing service, and the other is a low-severity issue in an internal tool. According to prioritization best practices, which finding should be addressed first?
Select an answer first - 13
A security scan of a microservices application reports a high-severity vulnerability in a service that processes payment transactions, and a medium-severity vulnerability in an internal reporting service that is not exposed to the internet. The team has limited resources. Which vulnerability should be fixed first?
Select an answer first - 14
A security scan identifies a medium-severity vulnerability in a web application: a lack of security headers, such as Content-Security-Policy (CSP). The recommended remediation is to add the missing headers. What is the most effective way to implement this remediation?
Select an answer first - 15
A security scan identifies a high-severity vulnerability in a web application: an insecure deserialization flaw in a legacy component. The recommended remediation is to upgrade the component to a patched version. However, the upgrade requires a significant refactor of dependent code. What is the most appropriate immediate action?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GitLab. “GITLAB-CERTIFIED-GIT-ASSOCIATE” is a trademark of its owner, used for identification only.