
GitLabCertified Security Associate
Domain 2Objective 1
Configure Secret Detection GITLAB-CERTIFIED-SECURITY-SPECIALIST Practice Questions (Page 5)
Part of the Secret and Dependency Scanning domain, which makes up ~21% of our current practice bank.
24questions here
5free pages
6concepts
Questions 21–24
- 21
A team wants to run secret detection only on the default branch and not on feature branches to save pipeline time. They are using the standard `secret_detection` job. What should they do?
Select an answer first - 22
A security team is investigating a potential secret leak. The secret detection finding in the merge request shows a token, but the developer claims it is a test token that was rotated. The team wants to confirm whether the token is still active. What is the best way to verify?
Select an answer first - 23
A security team wants to create a custom rule that detects a specific internal token format. They also want to ensure that the rule does not flag tokens in test files. They have a ruleset file that defines the rule. What should they add to the ruleset?
Select an answer first - 24
What is the purpose of a ruleset in GitLab secret detection?
Select an answer first
Finished these 4 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to GITLAB-CERTIFIED-SECURITY-SPECIALIST
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GitLab. “GITLAB-CERTIFIED-SECURITY-SPECIALIST” is a trademark of its owner, used for identification only.