
GitLabCertified Security Associate
Domain 5Objective 2
Triage and Remediate Vulnerabilities GITLAB-CERTIFIED-SECURITY-SPECIALIST Practice Questions (Page 2)
Part of the Vulnerability Management domain, which makes up ~16% of our current practice bank.
27questions here
6free pages
5concepts
Questions 6–10
- 6
A vulnerability scanner reports a medium-severity finding in a company's internal file server. The finding indicates that the server is running an outdated version of a file-sharing protocol that could allow information disclosure. The server is only accessible to authenticated employees and contains non-confidential project files. What should the security analyst do during triage?
Select an answer first - 7
Why is documentation of vulnerability triage decisions important for audit and compliance?
Select an answer first - 8
What does the CVSS base score primarily measure?
Select an answer first - 9
A security team remediated a SQL injection vulnerability in a web application by adding input validation. After the fix, the team re-ran the vulnerability scanner and the finding was no longer reported. However, a penetration tester later found that the input validation could be bypassed with a specific encoding technique. What should the team do?
Select an answer first - 10
A company's web application has a vulnerability that allows an attacker to upload malicious files. The application is critical to business operations, and the team cannot take it offline for patching. Which remediation strategy should the team apply?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GitLab. “GITLAB-CERTIFIED-SECURITY-SPECIALIST” is a trademark of its owner, used for identification only.