
GitLabCertified Security Associate
Domain 5Objective 2
Triage and Remediate Vulnerabilities GITLAB-CERTIFIED-SECURITY-SPECIALIST Practice Questions (Page 4)
Part of the Vulnerability Management domain, which makes up ~16% of our current practice bank.
27questions here
6free pages
5concepts
Questions 16–20
- 16
A security administrator remediated a vulnerability in a database by applying a vendor patch. The administrator wants to verify the patch did not break the application that uses the database. What should the administrator do?
Select an answer first - 17
Which remediation action directly addresses a vulnerability caused by a misconfigured firewall rule?
Select an answer first - 18
A security analyst is triaging two vulnerabilities in a company's environment. Vulnerability A has a CVSS base score of 7.5 and affects a public-facing web server that handles payment transactions. Vulnerability B has a CVSS base score of 9.0 and affects an internal development server that contains no production data. Both vulnerabilities are remotely exploitable. Which vulnerability should be remediated first?
Select an answer first - 19
A security team remediated a critical vulnerability in a production database server. The team applied a vendor patch, verified the fix, and closed the finding in the vulnerability management tool. A compliance auditor later asks for evidence of the remediation. What should the team provide to satisfy the audit requirement?
Select an answer first - 20
A security analyst is triaging a vulnerability report for a company's email server. The vulnerability is a denial-of-service (DoS) flaw that requires an authenticated account to exploit. The email server is critical to business operations, and the company has a strict uptime requirement. What should the analyst prioritize during triage?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GitLab. “GITLAB-CERTIFIED-SECURITY-SPECIALIST” is a trademark of its owner, used for identification only.