
GitLabCertified Security Associate
Domain 1Objective 1
Implement Static Application Security Testing (SAST) GITLAB-CERTIFIED-SECURITY-SPECIALIST Practice Questions (Page 1)
Part of the Static and Dynamic Application Security Testing domain, which makes up ~19% of our current practice bank.
24questions here
5free pages
7concepts
Questions 1–5
- 1
A team uses GitLab SAST on a monorepo containing both a Ruby on Rails API and a React frontend. The SAST scan is producing many findings in the `vendor/` directory that are not relevant to the team. They want to exclude this directory from scanning while keeping all other analyzers active. What is the most efficient way to achieve this?
Select an answer first - 2
A team has SAST enabled in their pipeline. Recently, the SAST job started failing because one of the analyzers crashed due to a memory limit. The team wants the pipeline to continue even if the SAST job fails, but they still want the scan results to appear in merge requests. What should they configure?
Select an answer first - 3
A large organization has multiple projects using GitLab SAST. They want to enforce a policy that blocks merge requests if any 'Critical' vulnerability is found, but they want to allow 'High' and lower severities to be merged without approval. They also want to exempt a specific project from this policy because it is a legacy application that is being decommissioned. How should they implement this?
Select an answer first - 4
In a GitLab CI/CD pipeline, how do you enable SAST for a project?
Select an answer first - 5
A development team wants to enforce a security gate so that merge requests cannot be merged if SAST finds any 'High' or 'Critical' severity vulnerabilities. They have already enabled SAST in the pipeline and the findings appear in merge requests. What additional configuration is required to enforce this gate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GitLab. “GITLAB-CERTIFIED-SECURITY-SPECIALIST” is a trademark of its owner, used for identification only.