
GitLabCertified Security Associate
Domain 3Objective 1
Implement Container Scanning GITLAB-CERTIFIED-SECURITY-SPECIALIST Practice Questions (Page 4)
Part of the Container Scanning domain, which makes up ~14% of our current practice bank.
27questions here
6free pages
7concepts
Questions 16–20
- 16
A container scan reports a critical vulnerability in a base image. The team has already upgraded the base image in a merge request, but the vulnerability still appears in the scan report. What is the most likely reason?
Select an answer first - 17
In the GitLab security lifecycle, where does container scanning typically fit?
Select an answer first - 18
What is the default behavior of container scanning in a merge request pipeline?
Select an answer first - 19
A container scan report lists a vulnerability with a CVSS score of 7.5 and a severity of 'High'. The vulnerability is in a package that is used only in a development tool that is not included in the production image. The team wants to reduce noise in the report. What is the best action?
Select an answer first - 20
A container scan report lists a vulnerability with a CVSS score of 9.8 and a severity of 'Critical'. The vulnerability is in a library that is not used at runtime. What is the best course of action?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GitLab. “GITLAB-CERTIFIED-SECURITY-SPECIALIST” is a trademark of its owner, used for identification only.