Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GitLab logo

GitLabCertified Security Associate

Domain 5Objective 1

Manage Vulnerabilities Across the DevSecOps Lifecycle GITLAB-CERTIFIED-SECURITY-SPECIALIST Practice Questions (Page 4)

Part of the Vulnerability Management domain, which makes up ~16% of our current practice bank.

24questions here
5free pages
6concepts

Questions 16–20

  1. 16application · medium

    A security manager needs to communicate the current vulnerability posture to the executive team. The manager wants to show trends over time and highlight areas that need attention. Which GitLab feature is most appropriate for this?

    Select an answer first
  2. 17foundation · easy

    In GitLab, which feature is used to assign a vulnerability to a specific team member for remediation and to track its status?

    Select an answer first
  3. 18expert · hard

    A security analyst is triaging a vulnerability that has a CVSS score of 7.5 and is present in a library used in a public-facing API. The library is not directly exposed, but the API processes user input that could reach the vulnerable code. There is no known exploit. What should the analyst do?

    Select an answer first
  4. 19foundation · easy

    During triage, a vulnerability is found in a library that is only used in a non-critical internal tool. The vulnerability has a high CVSS score but is not directly accessible to external users. What should be the primary consideration when prioritizing this vulnerability?

    Select an answer first
  5. 20expert · medium

    A company wants to enforce a security gate that blocks the deployment of a container image if it contains a critical vulnerability. They use GitLab CI/CD with container scanning. What is the most effective way to implement this?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GitLab. “GITLAB-CERTIFIED-SECURITY-SPECIALIST” is a trademark of its owner, used for identification only.