
GitLabCertified Security Associate
Domain 3Objective 2
Assess Container Image Vulnerabilities GITLAB-CERTIFIED-SECURITY-SPECIALIST Practice Questions (Page 2)
Part of the Container Scanning domain, which makes up ~14% of our current practice bank.
20questions here
4free pages
5concepts
Questions 6–10
- 6
A team is new to GitLab and wants to understand how container scanning fits into their CI/CD workflow. They have a Dockerfile that builds an image and they want to scan it before pushing to the registry. What is the correct workflow?
Select an answer first - 7
Which of the following are sources of vulnerabilities that GitLab container scanning can detect?
Select an answer first - 8
A security team is evaluating a container image for production. The scan report shows a 'High' severity vulnerability in a package that is used only in a non-default configuration. The team has a policy to remediate all High and Critical vulnerabilities, but the package is required for a feature that is not yet enabled. What is the most appropriate action?
Select an answer first - 9
A container scanning report shows a vulnerability with a 'Low' severity in a package that is used in the application. The team has a policy to fix all vulnerabilities, but the fix requires a major version upgrade that could break compatibility. What is the most appropriate action?
Select an answer first - 10
A developer wants to scan a container image that includes a Python application. Which of the following components would GitLab container scanning check for vulnerabilities?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GitLab. “GITLAB-CERTIFIED-SECURITY-SPECIALIST” is a trademark of its owner, used for identification only.