Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GitLab logo

GitLabCertified Fundamentals Associate

Domain 5Objective 2

Interpret Security Scan Results GITLAB-CERTIFIED-GIT-ASSOCIATE Practice Questions (Page 5)

Part of the Security Scanning Basics domain, which makes up ~13% of our current practice bank.

23questions here
5free pages
3concepts

Questions 21–23

  1. 21application · medium

    A security scan identifies a high-severity vulnerability in a web application: a path traversal in a file download feature. The recommended remediation is to validate file paths and restrict access to the intended directory. What is the most effective way to implement this remediation?

    Select an answer first
  2. 22application · medium

    A security scan report for a web application lists a vulnerability in a third-party JavaScript library used on the login page. The library is outdated and has a known remote code execution (RCE) vulnerability. The team has a release scheduled for next week. What should the team do?

    Select an answer first
  3. 23application · medium

    A security scan of a web application reports a medium-severity vulnerability in a public-facing contact form that could allow spam submissions. The same scan reports a low-severity vulnerability in an internal reporting tool that could allow information disclosure. The team has limited time this week. Which vulnerability should be addressed first?

    Select an answer first
Finished these 3 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GitLab. “GITLAB-CERTIFIED-GIT-ASSOCIATE” is a trademark of its owner, used for identification only.