Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GitLab logo

GitLabCertified Security Associate

Domain 1Objective 1

Implement Static Application Security Testing (SAST) GITLAB-CERTIFIED-SECURITY-SPECIALIST Practice Questions (Page 5)

Part of the Static and Dynamic Application Security Testing domain, which makes up ~19% of our current practice bank.

24questions here
5free pages
7concepts

Questions 21–24

  1. 21foundation · easy

    Which GitLab SAST variable is used to exclude specific paths from being scanned?

    Select an answer first
  2. 22expert · medium

    A team has a monorepo with multiple independent services. They want to run SAST on the entire repository, but they are concerned that a failure in one service's scan will block the pipeline for all services. They want to isolate failures so that a scan failure in one service does not prevent other services from being deployed. What is the best approach?

    Select an answer first
  3. 23application · medium

    A security team wants to add a custom SAST analyzer that checks for a proprietary security pattern in their internal configuration files. They have written a script that outputs findings in the GitLab SAST report format. How should they integrate this script into the pipeline?

    Select an answer first
  4. 24foundation · easy

    How does GitLab display SAST findings in a merge request?

    Select an answer first
Finished these 4 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GitLab. “GITLAB-CERTIFIED-SECURITY-SPECIALIST” is a trademark of its owner, used for identification only.