
GitLabCertified Security Associate
Domain 1Objective 2
Implement Dynamic Application Security Testing (DAST) GITLAB-CERTIFIED-SECURITY-SPECIALIST Practice Questions (Page 2)
Part of the Static and Dynamic Application Security Testing domain, which makes up ~19% of our current practice bank.
23questions here
5free pages
8concepts
Questions 6–10
- 6
During the scanning phase of a DAST workflow, what does the tool primarily do?
Select an answer first - 7
What is a false positive in the context of DAST?
Select an answer first - 8
What is a common limitation of DAST?
Select an answer first - 9
A security analyst is reviewing a DAST report and finds a vulnerability with a 'High' severity rating. The evidence shows that the vulnerability was detected in a parameter that is only used in a legacy feature that is no longer accessible from the main application. The analyst checks the application and confirms that the feature is still accessible via a direct URL. What should the analyst do?
Select an answer first - 10
After fixing a vulnerability identified by DAST, what is the recommended next step?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GitLab. “GITLAB-CERTIFIED-SECURITY-SPECIALIST” is a trademark of its owner, used for identification only.