
GitLabCertified Security Associate
Domain 4Objective 3
Enforce Policy Compliance GITLAB-CERTIFIED-SECURITY-SPECIALIST Practice Questions (Page 3)
Part of the Security Policies and Approvals domain, which makes up ~19% of our current practice bank.
25questions here
5free pages
6concepts
Questions 11–15
- 11
How can GitLab integrate with an external compliance tool to extend enforcement capabilities?
Select an answer first - 12
A company uses an external GRC (governance, risk, and compliance) tool to manage compliance evidence. The security team wants to automatically send compliance pipeline results to the GRC tool. The GRC tool only accepts data via a specific API. What is the best way to integrate GitLab with the GRC tool?
Select an answer first - 13
How do you apply a compliance pipeline to a project in GitLab?
Select an answer first - 14
A healthcare organization uses a compliance pipeline to run security scanning on all projects. The pipeline is defined in a separate repository and referenced by all projects. Recently, a developer accidentally modified the pipeline definition in a project's own .gitlab-ci.yml, bypassing the required scan. What is the most effective way to prevent this bypass?
Select an answer first - 15
A compliance officer needs to see a list of all policy violations that have occurred in the last 30 days across all projects. Which report or view should the officer use?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GitLab. “GITLAB-CERTIFIED-SECURITY-SPECIALIST” is a trademark of its owner, used for identification only.