
GitLabCertified Fundamentals Associate
Domain 5Objective 1
Set up Basic Security Scanning GITLAB-CERTIFIED-GIT-ASSOCIATE Practice Questions (Page 5)
Part of the Security Scanning Basics domain, which makes up ~13% of our current practice bank.
27questions here
6free pages
5concepts
Questions 21–25
- 21
A team is developing a Python application and wants to scan for security vulnerabilities in the source code. They also want to scan the Python dependencies for known vulnerabilities. Which combination of scanning types should they configure?
Select an answer first - 22
A team has a merge request that is blocked by a 'Critical' vulnerability. The vulnerability is a false positive, but the team needs to merge the MR today. The team wants to maintain an audit trail of the decision. What is the best course of action?
Select an answer first - 23
When are security scans typically triggered in a GitLab pipeline?
Select an answer first - 24
A team has a pipeline that includes SAST and DAST. The SAST job runs successfully, but the DAST job fails because the application is not deployed. The team wants to ensure DAST only runs after the application is deployed. What is the best approach?
Select an answer first - 25
A team wants to scan their container image for known vulnerabilities in the base OS packages and application dependencies. Which GitLab security scanning type should they configure?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GitLab. “GITLAB-CERTIFIED-GIT-ASSOCIATE” is a trademark of its owner, used for identification only.