
GitLabCertified Security Associate
Domain 5Objective 2
Triage and Remediate Vulnerabilities GITLAB-CERTIFIED-SECURITY-SPECIALIST Practice Questions (Page 3)
Part of the Vulnerability Management domain, which makes up ~16% of our current practice bank.
27questions here
6free pages
5concepts
Questions 11–15
- 11
Which remediation strategy is most appropriate when a security patch for a vulnerability is not yet available?
Select an answer first - 12
A DevOps team uses GitLab to manage a public-facing web application. A vulnerability scan identifies a critical-severity flaw in a third-party JavaScript library used by the frontend. The library is loaded directly from the application's server, and the flaw allows reflected cross-site scripting (XSS). The team cannot update the library for two weeks due to a contractual freeze on dependency changes. Which remediation strategy should the team apply in the interim?
Select an answer first - 13
A system administrator applied a security patch to a Linux server to remediate a privilege escalation vulnerability. After the patch, the administrator wants to verify that the remediation was effective without introducing regressions. Which verification step should the administrator perform?
Select an answer first - 14
During vulnerability triage, which sequence of steps is most appropriate for prioritizing reported vulnerabilities?
Select an answer first - 15
A security analyst triaged a vulnerability in a production application and decided to accept the risk because the application is scheduled for decommissioning in 30 days. The analyst documented the decision in the vulnerability management tool. A compliance auditor later questions why the vulnerability was not remediated. What should the analyst provide to justify the decision?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GitLab. “GITLAB-CERTIFIED-SECURITY-SPECIALIST” is a trademark of its owner, used for identification only.