Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GitLab logo

GitLabCertified Security Associate

Domain 5Objective 2

Triage and Remediate Vulnerabilities GITLAB-CERTIFIED-SECURITY-SPECIALIST Practice Questions (Page 1)

Part of the Vulnerability Management domain, which makes up ~16% of our current practice bank.

27questions here
6free pages
5concepts

Questions 1–5

  1. 1application · medium

    A company discovers a vulnerability in a legacy application that is no longer supported by the vendor. The application is critical to daily operations and cannot be replaced for six months. The vulnerability allows an authenticated user to escalate privileges. Which remediation strategy is most appropriate in this situation?

    Select an answer first
  2. 2application · medium

    A security team remediated a vulnerability in a production server by applying a configuration change. The team verified the change and closed the finding. A month later, an auditor asks for evidence of the remediation. What should the team provide?

    Select an answer first
  3. 3foundation · easy

    What information should be recorded in a vulnerability remediation report?

    Select an answer first
  4. 4application · medium

    A security team is reviewing a vulnerability in a web application that stores customer payment information. The vulnerability has a CVSS base score of 6.5, but the application is behind a WAF and requires multi-factor authentication (MFA) for all users. The team must decide whether to remediate the vulnerability or accept the risk. What should the team do?

    Select an answer first
  5. 5application · medium

    A security analyst at a financial services company is triaging a newly reported vulnerability in an internal customer relationship management (CRM) application. The vulnerability has a CVSS base score of 9.8, but the application is only accessible from the internal corporate network, contains no sensitive customer data, and is scheduled for decommissioning in 60 days. The analyst must decide how to prioritize this finding. What should the analyst do first?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GitLab. “GITLAB-CERTIFIED-SECURITY-SPECIALIST” is a trademark of its owner, used for identification only.