
GitLabCertified Security Associate
Domain 2Objective 3
Remediate Detected Findings GITLAB-CERTIFIED-SECURITY-SPECIALIST Practice Questions (Page 1)
Part of the Secret and Dependency Scanning domain, which makes up ~21% of our current practice bank.
27questions here
6free pages
7concepts
Questions 1–5
- 1
A dependency scan flags a moderate vulnerability in a library that is a transitive dependency of a core package. The direct package has not released an update that fixes it. What is the most appropriate remediation action?
Select an answer first - 2
When prioritizing secret detection findings, which factor is MOST important to consider?
Select an answer first - 3
How can merge requests be used to facilitate remediation of a security finding?
Select an answer first - 4
A developer marked a dependency finding as a false positive because the vulnerable function is never called. Later, a security review reveals the function is reachable through an indirect code path. What should be done?
Select an answer first - 5
A secret detection scan finds a hardcoded API key in a configuration file. The key is for a third-party service and is currently active. What is the immediate remediation step?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GitLab. “GITLAB-CERTIFIED-SECURITY-SPECIALIST” is a trademark of its owner, used for identification only.