Pre-Winter Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: clap70

GH-500 GitHub Advanced Security Exam Questions and Answers

Questions 4

You are viewing a code scanning alert. What detail is included in the alert?

Options:

A.

The secret checked into the repository

B.

The Common Weakness Enumeration (CWE) submission date

C.

The GitHub username of anyone who has Read access to the repository

D.

The line of code that triggered the alert

Buy Now
Questions 5

Why should you dismiss a code scanning alert?

Options:

A.

If you fix the code that triggered the alert

B.

To prevent developers from introducing new problems

C.

If it includes an error in code that is used only for testing

D.

If there is a production error in your code

Buy Now
Questions 6

To be compatible with code scanning, what data format must third-party code scanning tools use for output?

Options:

A.

Static Analysis Results Interchange Format (SARIF)

B.

YAML

C.

ESLint

D.

ECMAScript

Buy Now
Questions 7

Which alerts do you see in the repository's Security tab? (Each answer presents part of the solution. Choose three.)

Options:

A.

Repository permissions

B.

Secret scanning alerts

C.

Dependabot alerts

D.

Security status alerts

E.

Code scanning alerts

Buy Now
Questions 8

Which of the following features helps to prioritize secret scanning alerts that present an immediate risk?

Options:

A.

Non-provider patterns

B.

Push protection

C.

Custom pattern dry runs

D.

Secret validation

Buy Now
Questions 9

In a private repository, what minimum requirements does GitHub need to generate a dependency graph? (Each answer presents part of the solution. Choose two.)​

Options:

A.

Read-only access to all the repository's files

B.

Dependency graph enabled at the organization level for all new private repositories

C.

Write access to the dependency manifest and lock files for an enterprise

D.

Read-only access to the dependency manifest and lock files for a repository​

Buy Now
Questions 10

Secret scanning will scan:​

Options:

A.

A continuous integration system.

B.

Any Git repository.

C.

The GitHub repository.

D.

External services.​

Buy Now
Questions 11

Which of the following statements best describes secret scanning push protection?​

Options:

A.

Commits that contain secrets are blocked before code is added to the repository.

B.

Secret scanning alerts must be closed before a branch can be merged into the repository.

C.

Buttons for sensitive actions in the GitHub UI are disabled.

D.

Users need to reply to a 2FA challenge before any push events.​

Buy Now
Questions 12

What happens when you enable secret scanning on a private repository?

Options:

A.

Repository administrators can view Dependabot alerts.

B.

Your team is subscribed to security alerts.

C.

GitHub performs a read-only analysis on the repository.

D.

Dependency review, secret scanning, and code scanning are enabled.

Buy Now
Questions 13

Assuming security and analysis features are not configured at the repository, organization, or enterprise level, secret scanning is enabled on:

Options:

A.

Public repositories

B.

All new repositories within your organization

C.

User-owned private repositories

D.

Private repositories

Buy Now
Questions 14

By default, which role can enable Dependabot alerts?

Options:

A.

Repository administrators

B.

Repository maintainers

C.

Security analysts

D.

Outside collaborators

Buy Now
Questions 15

Who can fix a code scanning alert on a private repository?​

Options:

A.

Users who have the Triage role within the repository

B.

Users who have Read permissions within the repository

C.

Users who have Write access to the repository

D.

Users who have the security manager role within the repository​

Buy Now
Questions 16

Where can a user change a repository's code scanning severity threshold that fails a pull request status check?

Options:

A.

Security tab

B.

Pull Requests tab

C.

Actions tab

D.

Settings tab

Buy Now
Questions 17

What is the format of the GitHub security advisory form?

Options:

A.

A CVE Numbering Authority (CNA) description format

B.

A Dependabot alert sent to the affected repositories

C.

A form matching the MITRE database security advisory format

D.

A form matching the Common Vulnerabilities and Exposures (CVE) description format

Buy Now
Questions 18

You want to specify a CodeQL configuration file for a GitHub Actions workflow. Which input to the init step in the CodeQL action do you use to pass the path of the configuration file?

Options:

A.

config-file

B.

source-root

C.

db-location

D.

queries

Buy Now
Questions 19

What is the best method to ensure all new code is scanned for vulnerabilities?

Options:

A.

Add the extended suite.

B.

Configure code owners.

C.

Set up a security policy.

D.

Configure code scanning.

Buy Now
Questions 20

What role is required to change a repository's code scanning severity threshold that fails a pull request status check?

Options:

A.

Maintain

B.

Write

C.

Triage

D.

Admin

Buy Now
Questions 21

After defining a secret scanning custom pattern, what is the final step before publishing the pattern?

Options:

A.

Defining a custom pattern

B.

Enabling push protection

C.

Adding additional match requirements

D.

Performing a dry run

Buy Now
Questions 22

A dependency has a known vulnerability. What does the warning message include?

Options:

A.

The security impact of these changes

B.

An easily understandable visualization of dependency change

C.

How many projects use these components

D.

A brief description of the vulnerability

Buy Now
Questions 23

In the pull request, how can developers avoid adding new dependencies with known vulnerabilities?

Options:

A.

Enable Dependabot alerts.

B.

Add Dependabot rules.

C.

Add a workflow with the dependency review action.

D.

Enable Dependabot security updates.

Buy Now
Questions 24

Where can you view code scanning results from CodeQL analysis?

Options:

A.

The repository's code scanning alerts

B.

A CodeQL database

C.

A CodeQL query pack

D.

At Security advisories

Buy Now
Questions 25

When does Dependabot alert you of a vulnerability in your software development process?

Options:

A.

When a pull request adding a vulnerable dependency is opened

B.

As soon as a vulnerable dependency is detected

C.

As soon as a pull request is opened by a contributor

D.

When Dependabot opens a pull request to update a vulnerable dependency

Buy Now
Questions 26

You have enabled security updates for a repository. When does GitHub mark a Dependabot alert as resolved for that repository?

Options:

A.

When Dependabot creates a pull request to update dependencies

B.

When you dismiss the Dependabot alert

C.

When the pull request checks are successful

D.

When you merge a pull request that contains a security update

Buy Now
Questions 27

Where can you find the vulnerable dependencies that GitHub detected in your repository?

Options:

A.

In Dependabot alerts

B.

In secret scanning alerts

C.

In security advisories

D.

In code scanning alerts

Buy Now
Questions 28

Which of the following is the most complete method for Dependabot to find vulnerabilities in third-party dependencies?

Options:

A.

Dependabot reviews manifest files in the repository

B.

CodeQL analyzes the code and raises vulnerabilities in third-party dependencies

C.

A dependency graph is created, and Dependabot compares the graph to the GitHub Advisory database

D.

The build tool finds the vulnerable dependencies and calls the Dependabot API

Buy Now
Questions 29

Which organization policy lets organizations choose whether to allow members to view dependency insights?

Options:

A.

Enable all

B.

Enabled

C.

Disabled

D.

No policy

Buy Now
Questions 30

What should you do after receiving an alert about a dependency added in a pull request?

Options:

A.

Disable Dependabot alerts for all repositories owned by your organization

B.

Fork the branch and deploy the new fork

C.

Update the vulnerable dependencies before the branch is merged

D.

Deploy the code to your default branch

Buy Now
Questions 31

Which of the following steps should you follow to integrate CodeQL into a third-party continuous integration system? (Each answer presents part of the solution. Choose three.)

Options:

A.

Process alerts

B.

Analyze code

C.

Upload scan results

D.

Install the CLI

E.

Write queries

Buy Now
Questions 32

As a repository owner, you do not want to run a GitHub Actions workflow when changes are made to any .txt or markdown files. How would you adjust the event trigger for a pull request that targets the main branch? (Each answer presents part of the solution. Choose three.)

    on:

    pull_request:

    branches: [main]

Options:

A.

- '/*.md'

B.

- '/*.txt'

C.

paths:

D.

paths-ignore:

E.

- 'docs/*.md'

Buy Now
Questions 33

You are configuring a CodeQL workflow for compiled languages. What happens if your workflow uses a language matrix?

Options:

A.

Analysis of other languages in your repository will fail unless you supply explicit build commands.

B.

Autobuild attempts to build the supported language that has the most source files in the repository.

C.

You may need to install additional software to use the autobuild process.

D.

Autobuild attempts to build each of the languages listed in the matrix.

Buy Now
Questions 34

What does code scanning do?

Options:

A.

It contacts maintainers to ask them to create security advisories if a vulnerability is found

B.

It prevents code pushes with vulnerabilities as a pre-receive hook

C.

It analyzes a GitHub repository to find security vulnerabilities

D.

It scans your entire Git history on branches present in your GitHub repository for any secrets

Buy Now
Questions 35

What is a benefit of using a custom CodeQL configuration file?

Options:

A.

It specifies a token that has access to the private repository.

B.

It automatically selects the package to use.

C.

It allows configuration options for multiple repositories in a single place.

D.

It disables packs from running the default query suite.

Buy Now
Questions 36

What happens when you remove someone's access to a private repository?

Options:

A.

Local clones of the private repository are deleted.

B.

Team access to a private repository is revoked.

C.

Their forks of that private repository are deleted.

D.

Confidential information is deleted.

Buy Now
Questions 37

Where is secret scanning enabled on a private repository?

Options:

A.

In the code security settings

B.

Within a repository ruleset

C.

Within a secret.yml file in the repository

D.

In the code scanning default setup settings

Buy Now
Exam Code: GH-500
Exam Name: GitHub Advanced Security Exam
Last Update: Oct 1, 2026
Questions: 125
GH-500 pdf

GH-500 PDF

$28.5  $94.99
GH-500 Engine

GH-500 Testing Engine

$33  $109.99
GH-500 PDF + Engine

GH-500 PDF + Testing Engine

$43.5  $144.99