Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GitLab logo

GitLabCertified Security Associate

Domain 1Objective 2

Implement Dynamic Application Security Testing (DAST) GITLAB-CERTIFIED-SECURITY-SPECIALIST Practice Questions (Page 3)

Part of the Static and Dynamic Application Security Testing domain, which makes up ~19% of our current practice bank.

23questions here
5free pages
8concepts

Questions 11–15

  1. 11foundation · easy

    Which of the following is a required configuration for a DAST scan?

    Select an answer first
  2. 12application · medium

    After running a DAST scan, a security analyst reviews the report and finds a vulnerability flagged as 'High' severity with evidence showing a reflected XSS payload in a URL parameter. The analyst checks the application code and confirms that the parameter is properly encoded before being rendered. What should the analyst do next?

    Select an answer first
  3. 13foundation · easy

    Which of the following is a key difference between SAST and DAST?

    Select an answer first
  4. 14application · medium

    A security team is implementing DAST for a web application that heavily uses JavaScript to render content dynamically. The team is concerned that the DAST scanner may not be able to crawl all the dynamic content. What should they do to mitigate this limitation?

    Select an answer first
  5. 15foundation · easy

    Which type of vulnerability is DAST specifically well-suited to detect?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GitLab. “GITLAB-CERTIFIED-SECURITY-SPECIALIST” is a trademark of its owner, used for identification only.