Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GitLab logo

GitLabCertified Fundamentals Associate

Domain 5Objective 2

Interpret Security Scan Results GITLAB-CERTIFIED-GIT-ASSOCIATE Practice Questions (Page 4)

Part of the Security Scanning Basics domain, which makes up ~13% of our current practice bank.

23questions here
5free pages
3concepts

Questions 16–20

  1. 16expert · hard

    A security scan of a web application reports a high-severity vulnerability in a public-facing file upload feature that could allow an attacker to upload malicious files. The same scan reports a medium-severity vulnerability in an internal logging system that could allow an attacker to view sensitive logs. The team has a release scheduled in one week. What is the best course of action?

    Select an answer first
  2. 17expert · hard

    A security scan of a web application reports a critical-severity vulnerability in a public-facing API that could allow an attacker to access other users' data. The same scan reports a high-severity vulnerability in an internal database that could allow an attacker to modify data. The team has a release scheduled in one week. What is the best course of action?

    Select an answer first
  3. 18application · medium

    A security scan identifies a medium-severity vulnerability in a web application: a server-side request forgery (SSRF) in a URL preview feature. The recommended remediation is to validate and restrict the URLs that can be fetched. What is the most effective way to implement this remediation?

    Select an answer first
  4. 19expert · hard

    A security scan of a web application reports a low-severity vulnerability in a public-facing search feature that could allow information disclosure. The same scan reports a high-severity vulnerability in an internal admin panel that could allow privilege escalation. The company is about to launch a new marketing campaign that will drive significant traffic to the search feature. What is the best course of action?

    Select an answer first
  5. 20foundation · easy

    A security scan report lists a vulnerability with a CVSS score of 9.8. According to common severity ratings, how should this finding be classified?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GitLab. “GITLAB-CERTIFIED-GIT-ASSOCIATE” is a trademark of its owner, used for identification only.