You can see it againUnder pressure people bring back shapes and positions long after the wording has gone.
Picture superiority · Shepard 1967, Standing 1973
The GitLab Certified Security Specialist certification validates your ability to embed security into every stage of the DevOps lifecycle using GitLab's built-in security features. It is designed for security professionals and DevOps practitioners who want to demonstrate they can configure, manage, and act on security scanning and compliance controls within GitLab. Earning this credential shows you can operationalize DevSecOps and shift security left with confidence.
What this certification covers, who it is written for, and what the exam itself looks like on the day.
What it validates, who it is written for, and the experience it assumes.
The GitLab Certified Security Specialist certification confirms that you can leverage GitLab's integrated security capabilities to protect software delivery pipelines. It covers the configuration and management of security scanners, vulnerability management, compliance frameworks, and security policies within GitLab, enabling you to identify and remediate risks early in the development process.
This certification is for security engineers, DevOps engineers, and application security professionals who are responsible for integrating security into CI/CD workflows. By earning it, you demonstrate a practical understanding of GitLab's security features and how to use them to enforce security and compliance across the software development lifecycle.
This certification is for security professionals, DevOps engineers, and developers who are responsible for implementing and managing security controls within GitLab. It is ideal for those who want to validate their skills in using GitLab's security scanning, compliance, and vulnerability management features to protect their software delivery pipelines. You should have a solid understanding of GitLab's core features, including CI/CD pipelines, and be familiar with security concepts such as vulnerability scanning, compliance frameworks, and security policies. You are comfortable working in a DevOps environment and are looking to formalize your expertise in DevSecOps practices.
At least six months of hands-on experience with GitLab, including using CI/CD pipelines and security scanning features, is recommended. Experience configuring and running GitLab CI/CD pipelines; Familiarity with GitLab security scanning features such as SAST, DAST, and dependency scanning; Understanding of vulnerability management and compliance frameworks; Basic knowledge of security policies and how to enforce them in a DevOps environment
Every domain and objective GitLab measures, with the weight they carry on the exam.
The official GitLab exam outline · See the source
Everything GitLab publishes about sitting it, and nothing we inferred.
No mandatory prerequisites — this certification has no required predecessor exam or credential.
The path GitLab lays out, how the credential is kept, and where to book.
Step-by-step path to GitLab Certified Security Associate
GitLab certifications do not require renewal. Once earned, the GitLab Certified Security Specialist certification does not expire. Stay current with the latest technologies and maintain your certification.
Learn more about renewal requirementsThis certification is currently active and available. GitLab maintains this certification to validate current skills and industry relevance.
Register for the exam through GitLab Learn, GitLab’s authorized testing partner.
Schedule your examVisit the official GitLab certification page for exam policies and requirements.
View the official pageYour coach in the app reads what you have answered with the book closed and tells you one thing to do tonight. It will not count an answer you gave with the page open, and it will tell you when you are not ready.
See how the coach worksThis certification is a standalone credential focused on security. It does not require any other GitLab certification as a prerequisite, and it is not a prerequisite for any other GitLab certification.
The exam is delivered online and consists of multiple-choice questions. There is no separate hands-on lab component; however, the questions are designed to test practical knowledge of using GitLab's security features.
GitLab Learn allows you to retake the exam after a waiting period. Specific retake policies are provided on the exam registration page.
Results are typically provided immediately after completing the online exam, and your certification badge is issued shortly thereafter.
This credential is relevant for security engineers, DevSecOps engineers, application security analysts, and DevOps professionals who are responsible for integrating security into GitLab CI/CD pipelines.
No, GitLab certifications do not require renewal, so there is no recertification process. Once earned, the credential remains valid.
Every domain, every objective, and every concept GitLab measures — each one written out.





Every objective below is a page you can open and practise now, without an account.
The official GitLab exam outline · See the source
In front of every objective the practice pages are already there, free and without an account. This is one objective, opened.
24 questions on this objective, five to a page. Every range above is a real page, open now, with no account.
The curriculum tells you what is on the exam. Proving you know it is a different job — and it is the one the closed-book run does.
The whole bank is open. 5 questions to a page, every answer explained, and a discussion thread on each one.
Every objective, and every page range, is a link — so you can pick up exactly where you left off.
Short enough to finish, long enough to matter.
Not only which one is right — why the others are wrong.
Ask, answer, and vote. Every question has its own thread.
These are not trivia. Each one is written against a concept in the book, so when you get one wrong there is somewhere to go and find out why.

The pages shown here come from our AI-900 book — an example of how each concept is written in plain language and, where the idea needs one, drawn as a full page you can take in at a glance.





Three reasons, and each one is a real finding rather than a slogan.
You can see it againUnder pressure people bring back shapes and positions long after the wording has gone.
Picture superiority · Shepard 1967, Standing 1973
The whole idea at onceWhere it starts, what happens in the middle, what comes out, and the mistake to avoid.
Multimedia principle · Mayer
The look-alikes sit togetherThe pairs the exam tests are drawn side by side, so the difference is seen, not told.
Dual coding · PaivioYou are never asked to read a poster here — only to see how one is built. After that, every other page is legible at a glance.

The idea as a sequence, followed with a finger before a word is read.
What it is, how the machine learns it, when it is the right tool.
The distinction the exam tests, given its own box instead of buried in prose.
The sentence to carry into the exam room.
This is the part that teaches. The illustration and the written explanation stay where they are while you work, so a scenario stops being a memory test and becomes something you can simply look at.
A smartphone uses AI to unlock when the owner looks at the camera. Which AI capability is being used?

The same questions come back with the book closed — that run is the one that counts. After it, your coach picks one thing for tonight, sized to the time you have, and brings pages back before you lose them.
Testing effect · Roediger & Karpicke 2006 · spacing effect · Cepeda et al. 2006
Where the exam is defined, scheduled and scored.
We link to them rather than repeat them, so nothing here goes stale behind them.
We build from the official skills outline, not from a summary of it — 15 objectives, 93 concepts written under them, and free questions against every one. When GitLab changes the outline, this page changes with it.
That is the only question worth answering the night before, and no link answers it. You answer it by taking the questions with the book closed, and seeing what comes back.