Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GitLab logo

GitLabCertified Security Associate

Domain 5Objective 1

Manage Vulnerabilities Across the DevSecOps Lifecycle GITLAB-CERTIFIED-SECURITY-SPECIALIST Practice Questions (Page 2)

Part of the Vulnerability Management domain, which makes up ~16% of our current practice bank.

24questions here
5free pages
6concepts

Questions 6–10

  1. 6foundation · easy

    Which GitLab security scanning tool is used to identify vulnerabilities in the source code itself, such as SQL injection or insecure deserialization patterns, without executing the application?

    Select an answer first
  2. 7foundation · easy

    In a GitLab CI/CD pipeline, what is a security gate?

    Select an answer first
  3. 8application · medium

    A security team uses GitLab Vulnerability Report to manage a backlog of vulnerabilities. They notice that many vulnerabilities have been open for months without any update. The team wants to improve the remediation workflow. Which action would be most effective?

    Select an answer first
  4. 9foundation · easy

    In a GitLab DevSecOps pipeline, a developer commits code that introduces a vulnerable dependency. The vulnerability is detected by a dependency scanner and a vulnerability record is created. What is the correct sequence of stages in the vulnerability lifecycle from this point?

    Select an answer first
  5. 10foundation · easy

    A security manager wants to track the trend of vulnerabilities over time to see if the organization is improving its security posture. Which metric would be most useful for this purpose?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GitLab. “GITLAB-CERTIFIED-SECURITY-SPECIALIST” is a trademark of its owner, used for identification only.