
GitLabCertified Security Associate
Domain 1Objective 3
Interpret Application Security Scan Results GITLAB-CERTIFIED-SECURITY-SPECIALIST Practice Questions (Page 1)
Part of the Static and Dynamic Application Security Testing domain, which makes up ~19% of our current practice bank.
17questions here
4free pages
5concepts
Questions 1–5
- 1
When reviewing a SAST report, what does the 'confidence' field primarily indicate?
Select an answer first - 2
A security team reviews a SAST report for a large application and finds two critical-severity issues: (1) a SQL injection in an admin-only endpoint that is rarely used, and (2) a stored XSS in a public comment section that is heavily used. Both are confirmed true positives. The team has resources to fix only one issue this sprint. Which issue should be prioritized?
Select an answer first - 3
Which action is most appropriate when validating a SAST finding that flags a potential SQL injection?
Select an answer first - 4
Why is business impact an important factor when prioritizing vulnerabilities?
Select an answer first - 5
A DAST scan of a healthcare application reports a critical-severity finding for an unauthenticated API endpoint that returns patient data. The analyst reviews the request and response and confirms the data is exposed. However, the endpoint is rate-limited to 10 requests per minute per IP address. The analyst is deciding whether to escalate this finding. What should the analyst do?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GitLab. “GITLAB-CERTIFIED-SECURITY-SPECIALIST” is a trademark of its owner, used for identification only.