
GitLabCertified Security Associate
Domain 2Objective 3
Remediate Detected Findings GITLAB-CERTIFIED-SECURITY-SPECIALIST Practice Questions (Page 3)
Part of the Secret and Dependency Scanning domain, which makes up ~21% of our current practice bank.
27questions here
6free pages
7concepts
Questions 11–15
- 11
A scan reports a high-severity vulnerability in a library used only in a legacy internal tool that is scheduled for decommissioning in two months. The library has no known exploit in the wild, and the tool is not internet-facing. What is the most appropriate action?
Select an answer first - 12
What is the best way to confirm that a dependency vulnerability has been resolved after upgrading the package?
Select an answer first - 13
A secret detection finding flags a string that looks like an API key but is actually a test fixture. What is the appropriate action?
Select an answer first - 14
A dependency scan flags a critical vulnerability in a Python package used by a microservice. The maintainer has released a patched version. What is the most efficient way to remediate this finding using GitLab's built-in features?
Select an answer first - 15
A security team wants to get a high-level view of all open vulnerabilities across multiple projects in a group to plan remediation sprints. Which GitLab feature is best suited for this?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GitLab. “GITLAB-CERTIFIED-SECURITY-SPECIALIST” is a trademark of its owner, used for identification only.