
GitLabCertified Security Associate
Domain 1Objective 2
Implement Dynamic Application Security Testing (DAST) GITLAB-CERTIFIED-SECURITY-SPECIALIST Practice Questions (Page 1)
Part of the Static and Dynamic Application Security Testing domain, which makes up ~19% of our current practice bank.
23questions here
5free pages
8concepts
Questions 1–5
- 1
A security team is deciding which type of application security testing to implement for a legacy web application that has no source code available. The application is deployed and running in production. The team needs to identify vulnerabilities that an attacker could exploit against the running application. Which testing approach should they choose?
Select an answer first - 2
What is a common remediation strategy for a SQL injection vulnerability found by DAST?
Select an answer first - 3
A security analyst is reviewing a DAST report and finds a vulnerability with a 'Medium' severity rating. The evidence shows that the vulnerability was detected in a legacy endpoint that is no longer used by the application. What should the analyst do?
Select an answer first - 4
How is DAST typically integrated into GitLab CI/CD?
Select an answer first - 5
What is the purpose of the 'evidence' provided in a DAST scan result?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GitLab. “GITLAB-CERTIFIED-SECURITY-SPECIALIST” is a trademark of its owner, used for identification only.