Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GitLab logo

GitLabCertified Security Associate

Domain 3Objective 2

Assess Container Image Vulnerabilities GITLAB-CERTIFIED-SECURITY-SPECIALIST Practice Questions (Page 4)

Part of the Container Scanning domain, which makes up ~14% of our current practice bank.

20questions here
4free pages
5concepts

Questions 16–20

  1. 16application · medium

    A container scanning report for a Java application shows a vulnerability in the `log4j` library. The application uses Maven for dependency management. What is the most likely source of this vulnerability?

    Select an answer first
  2. 17application · medium

    A GitLab container scanning report for a Node.js application shows a vulnerability in the `lodash` package. The application's `package.json` lists `lodash` as a direct dependency. What is the most likely source of this vulnerability?

    Select an answer first
  3. 18foundation · easy

    What is the primary purpose of container image vulnerability scanning in GitLab?

    Select an answer first
  4. 19expert · hard

    A security engineer is reviewing a container scanning report for an image that will be deployed to a production environment. The report shows a 'Critical' vulnerability in a package that is only used during the build stage and is not present in the final image. The engineer needs to decide whether to block the deployment. What is the most appropriate action?

    Select an answer first
  5. 20expert · hard · select all that apply

    A container scanning report for a Ruby on Rails application shows vulnerabilities in both the `libssl` package and the `nokogiri` gem. The application is built using a Debian-based base image. Which of the following are valid sources for these vulnerabilities? Select all that apply.

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GitLab. “GITLAB-CERTIFIED-SECURITY-SPECIALIST” is a trademark of its owner, used for identification only.