
GitLabCertified Security Associate
Domain 5Objective 2
Triage and Remediate Vulnerabilities GITLAB-CERTIFIED-SECURITY-SPECIALIST Practice Questions (Page 5)
Part of the Vulnerability Management domain, which makes up ~16% of our current practice bank.
27questions here
6free pages
5concepts
Questions 21–25
- 21
A security analyst is triaging two vulnerabilities. Vulnerability A has a CVSS base score of 8.0 and affects a public-facing web server that hosts the company's marketing website, which contains no sensitive data. Vulnerability B has a CVSS base score of 6.5 and affects an internal application that processes employee payroll data. Both vulnerabilities are remotely exploitable. Which vulnerability should be remediated first?
Select an answer first - 22
A security team is triaging a vulnerability in a public-facing application. The vulnerability has a CVSS base score of 9.0 and allows remote code execution. The team has a patch available, but applying it requires a 15-minute downtime. The application has a 99.9% uptime SLA, and the team has a maintenance window scheduled for next week. What should the team do?
Select an answer first - 23
Which method is commonly used to verify that a vulnerability has been remediated?
Select an answer first - 24
Which factor is most directly considered when assessing the exploitability of a reported vulnerability during triage?
Select an answer first - 25
What is the primary purpose of verification after applying a remediation action?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GitLab. “GITLAB-CERTIFIED-SECURITY-SPECIALIST” is a trademark of its owner, used for identification only.