Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GitLab logo

GitLabCertified Security Associate

Domain 2Objective 1

Configure Secret Detection GITLAB-CERTIFIED-SECURITY-SPECIALIST Practice Questions (Page 5)

Part of the Secret and Dependency Scanning domain, which makes up ~21% of our current practice bank.

24questions here
5free pages
6concepts

Questions 21–24

  1. 21application · medium

    A team wants to run secret detection only on the default branch and not on feature branches to save pipeline time. They are using the standard `secret_detection` job. What should they do?

    Select an answer first
  2. 22expert · medium

    A security team is investigating a potential secret leak. The secret detection finding in the merge request shows a token, but the developer claims it is a test token that was rotated. The team wants to confirm whether the token is still active. What is the best way to verify?

    Select an answer first
  3. 23expert · medium

    A security team wants to create a custom rule that detects a specific internal token format. They also want to ensure that the rule does not flag tokens in test files. They have a ruleset file that defines the rule. What should they add to the ruleset?

    Select an answer first
  4. 24foundation · easy

    What is the purpose of a ruleset in GitLab secret detection?

    Select an answer first
Finished these 4 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GitLab. “GITLAB-CERTIFIED-SECURITY-SPECIALIST” is a trademark of its owner, used for identification only.