
GitLabCertified Security Associate
Domain 1Objective 3
Interpret Application Security Scan Results GITLAB-CERTIFIED-SECURITY-SPECIALIST Practice Questions (Page 2)
Part of the Static and Dynamic Application Security Testing domain, which makes up ~19% of our current practice bank.
17questions here
4free pages
5concepts
Questions 6–10
- 6
A SAST scan of a Java application reports a high-severity finding for an insecure deserialization vulnerability. The finding is in a library that is used by a legacy module that is scheduled for decommissioning in six months. The team is considering whether to fix the issue or accept the risk. What should the team do?
Select an answer first - 7
A security team reviews a SAST report for a web application and identifies three findings: (1) a SQL injection in a login endpoint that is publicly accessible, (2) a hardcoded API key in a test file that is not deployed, and (3) a minor information disclosure in an error message that is only visible to authenticated admins. The team has limited development capacity this sprint. Which finding should be addressed first?
Select an answer first - 8
Which factor should be considered FIRST when prioritizing vulnerabilities for remediation?
Select an answer first - 9
A SAST report identifies a hardcoded password in a configuration file. The password is used to connect to a database. The team confirms the finding is a true positive. What is the most appropriate remediation step?
Select an answer first - 10
What is the most appropriate remediation for a confirmed SQL injection vulnerability in a web application?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GitLab. “GITLAB-CERTIFIED-SECURITY-SPECIALIST” is a trademark of its owner, used for identification only.