
GitLabCertified Security Associate
Domain 2Objective 3
Remediate Detected Findings GITLAB-CERTIFIED-SECURITY-SPECIALIST Practice Questions (Page 5)
Part of the Secret and Dependency Scanning domain, which makes up ~21% of our current practice bank.
27questions here
6free pages
7concepts
Questions 21–25
- 21
A secret detection scan finds two issues: a valid production API key in a public repository, and a valid staging API key in a private repository. Both keys are active. Which should be prioritized for remediation?
Select an answer first - 22
A developer merged a merge request that upgrades a vulnerable JavaScript library. How can the team verify that the dependency finding is truly resolved?
Select an answer first - 23
A security team has a list of findings from secret and dependency scans. Which finding should be prioritized for immediate remediation?
Select an answer first - 24
After applying a fix for a secret detection finding, how can a developer verify the remediation was successful?
Select an answer first - 25
What is the recommended way to handle a dependency scanning finding that is a false positive?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GitLab. “GITLAB-CERTIFIED-SECURITY-SPECIALIST” is a trademark of its owner, used for identification only.