Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GitLab logo

GitLabCertified Security Associate

Domain 2Objective 3

Remediate Detected Findings GITLAB-CERTIFIED-SECURITY-SPECIALIST Practice Questions (Page 1)

Part of the Secret and Dependency Scanning domain, which makes up ~21% of our current practice bank.

27questions here
6free pages
7concepts

Questions 1–5

  1. 1application · medium

    A dependency scan flags a moderate vulnerability in a library that is a transitive dependency of a core package. The direct package has not released an update that fixes it. What is the most appropriate remediation action?

    Select an answer first
  2. 2foundation · easy

    When prioritizing secret detection findings, which factor is MOST important to consider?

    Select an answer first
  3. 3foundation · easy

    How can merge requests be used to facilitate remediation of a security finding?

    Select an answer first
  4. 4application · medium

    A developer marked a dependency finding as a false positive because the vulnerable function is never called. Later, a security review reveals the function is reachable through an indirect code path. What should be done?

    Select an answer first
  5. 5application · medium

    A secret detection scan finds a hardcoded API key in a configuration file. The key is for a third-party service and is currently active. What is the immediate remediation step?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GitLab. “GITLAB-CERTIFIED-SECURITY-SPECIALIST” is a trademark of its owner, used for identification only.