
GitLabCertified Security Associate
Domain 2Objective 3
Remediate Detected Findings GITLAB-CERTIFIED-SECURITY-SPECIALIST Practice Questions (Page 2)
Part of the Secret and Dependency Scanning domain, which makes up ~21% of our current practice bank.
27questions here
6free pages
7concepts
Questions 6–10
- 6
Which GitLab feature is specifically designed to help track and manage security findings across a project?
Select an answer first - 7
A developer has just received a security alert for a detected secret in a merge request. According to GitLab's standard remediation workflow, what is the FIRST step the developer should take?
Select an answer first - 8
A security scan on a large monorepo reports 50 dependency findings. 45 are in development-only tooling with CVSS scores below 4.0. Three are in a production-facing API with CVSS scores of 7.5, 8.1, and 9.0. Two are in a rarely-used internal admin tool with CVSS scores of 6.5. The team has limited capacity this sprint. What is the most appropriate prioritization strategy?
Select an answer first - 9
A dependency scanning finding reports a vulnerable version of a library. What is the recommended remediation action?
Select an answer first - 10
A critical vulnerability is found in a shared library used by five different projects. The fix requires a coordinated upgrade across all projects. The security team wants to ensure the remediation is tracked and completed. What is the most effective approach?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GitLab. “GITLAB-CERTIFIED-SECURITY-SPECIALIST” is a trademark of its owner, used for identification only.