Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GitLab logo

GitLabCertified Security Associate

Domain 1Objective 3

Interpret Application Security Scan Results GITLAB-CERTIFIED-SECURITY-SPECIALIST Practice Questions (Page 3)

Part of the Static and Dynamic Application Security Testing domain, which makes up ~19% of our current practice bank.

17questions here
4free pages
5concepts

Questions 11–15

  1. 11foundation · easy

    Which remediation is appropriate for a confirmed Cross-Site Scripting (XSS) vulnerability in a web application?

    Select an answer first
  2. 12foundation · easy

    What information is typically found in the 'evidence' section of a DAST finding?

    Select an answer first
  3. 13expert · hard

    A security team reviews a SAST report for a microservices architecture and finds two high-severity findings: (1) a SQL injection in the user service, which is publicly accessible, and (2) a command injection in the admin service, which is only accessible from the internal network. Both are confirmed true positives. The team has limited resources and must choose one to fix first. What should the team prioritize?

    Select an answer first
  4. 14foundation · easy

    What is the primary purpose of validating a scan finding?

    Select an answer first
  5. 15foundation · easy

    In a SAST finding, what does the 'location' field typically provide?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GitLab. “GITLAB-CERTIFIED-SECURITY-SPECIALIST” is a trademark of its owner, used for identification only.