
GitLabCertified Security Associate
Domain 1Objective 1
Implement Static Application Security Testing (SAST) GITLAB-CERTIFIED-SECURITY-SPECIALIST Practice Questions (Page 3)
Part of the Static and Dynamic Application Security Testing domain, which makes up ~19% of our current practice bank.
24questions here
5free pages
7concepts
Questions 11–15
- 11
A security team is using GitLab SAST and has configured a custom rule to detect a specific vulnerability pattern. The rule is producing many false positives because it matches a common code pattern that is not always vulnerable. The team wants to reduce false positives without excluding entire files or disabling the rule. What is the best approach?
Select an answer first - 12
Which GitLab SAST analyzer is designed for scanning Python code?
Select an answer first - 13
Which artifact file does the GitLab SAST job produce by default?
Select an answer first - 14
What is the primary purpose of Static Application Security Testing (SAST) in the software development lifecycle?
Select an answer first - 15
What is a 'false positive' in the context of SAST results?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GitLab. “GITLAB-CERTIFIED-SECURITY-SPECIALIST” is a trademark of its owner, used for identification only.