Weekend Sale Special - 75% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: fifty75ct

GH-500 GitHub Advanced Security Exam Questions and Answers

Questions 4

As a repository owner, you want to receive specific notifications, including security alerts, for an individual repository. Which repository notification setting should you use?

Options:

A.

Ignore

B.

Participating and @mentions

C.

All Activity

D.

Custom

Buy Now
Questions 5

By default, which role can enable Dependabot alerts?

Options:

A.

Repository administrators

B.

Repository maintainers

C.

Security analysts

D.

Outside collaborators

Buy Now
Questions 6

Assuming there is no custom Dependabot behavior configured, where possible, what does Dependabot do after sending an alert about a vulnerable dependency in a repository?

Options:

A.

Creates a pull request to upgrade the vulnerable dependency to the minimum possible secure version

B.

Scans repositories for vulnerable dependencies on a schedule and adds those files to a manifest

C.

Constructs a graph of all the repository's dependencies and public dependents for the default branch

D.

Scans any push to all branches and generates an alert for each vulnerable repository

Buy Now
Questions 7

Which security feature shows a vulnerable dependency in a pull request?

Options:

A.

Dependency graph

B.

Dependency review

C.

Dependabot alert

D.

The repository's Security tab

Buy Now
Questions 8

What is required to trigger code scanning on a specified branch?

Options:

A.

The repository must be private.

B.

Secret scanning must be enabled on the repository.

C.

Developers must actively maintain the repository.

D.

The workflow file must exist in that branch.

Buy Now
Questions 9

When using code scanning and GitHub Actions on Windows, what is the relative difference between the minute consumption of code scanning jobs and jobs on Linux runners?

Options:

A.

2x higher

B.

5x higher

C.

10x higher

D.

No difference

Buy Now
Questions 10

Which of the following steps should you follow to integrate CodeQL into a third-party continuous integration system? (Each answer presents part of the solution. Choose three.)

Options:

A.

Process alerts

B.

Analyze code

C.

Upload scan results

D.

Install the CLI

E.

Write queries

Buy Now
Questions 11

What step is required to run a SARIF-compatible (Static Analysis Results Interchange Format) tool on GitHub Actions?​

Options:

A.

Update the workflow to include a final step that uploads the results.

B.

By default, the CodeQL runner automatically uploads results to GitHub on completion.

C.

The CodeQL action uploads the SARIF file automatically when it completes analysis.

D.

Use the CLI to upload results to GitHub.​

Buy Now
Questions 12

Which of the following dependencies could trigger a Dependabot alert? (Each answer presents a complete solution. Choose two.)

Options:

A.

Indirect dependencies explicitly declared in a lockfile

B.

Loose dependencies declared in a manifest

C.

Direct dependencies explicitly declared in a manifest

D.

Direct dependencies at 08:00 UTC

Buy Now
Questions 13

Assuming that default security and analysis settings have not been changed at the repository, organization, or enterprise level, which scenario would generate a dependency graph for the repository?

Options:

A.

When a public repository has a new dependency added to its manifest file

B.

When a private repository is forked to be used as a dependent

C.

When a public repository is forked to be used as a dependent

D.

When a private repository has a new dependency added to its manifest file

Buy Now
Questions 14

What is the first step in CodeQL analysis?

Options:

A.

Converting results produced during query execution

B.

Running CodeQL queries against the database

C.

Preparing the code by creating a CodeQL database

D.

Interpreting the query results

Buy Now
Questions 15

What do you need to do before you can define a custom pattern for a repository?​

Options:

A.

Provide a regular expression for the format of your secret pattern.

B.

Add a secret scanning custom pattern.

C.

Enable secret scanning on the repository.

D.

Provide match requirements for the secret format.​

Stack Overflow

Buy Now
Questions 16

In a private repository, what minimum requirements does GitHub need to generate a dependency graph? (Each answer presents part of the solution. Choose two.)​

Options:

A.

Read-only access to all the repository's files

B.

Dependency graph enabled at the organization level for all new private repositories

C.

Write access to the dependency manifest and lock files for an enterprise

D.

Read-only access to the dependency manifest and lock files for a repository​

Buy Now
Questions 17

Which details do you have to provide to create a custom pattern for secret scanning? (Each answer presents part of the solution. Choose two.)

Options:

A.

The secret format

B.

The name of the pattern

C.

A list of repositories to scan

D.

Additional match requirements for the secret format

Buy Now
Questions 18

You need to run code scanning when files are modified in a specific directory. Which option can be used to complete line 3 in the workflow fragment below?

1. on:

2. push:

3.

Options:

A.

**foo

B.

(

C.

?

D.

paths:

Buy Now
Questions 19

Who can fix a code scanning alert on a private repository?​

Options:

A.

Users who have the Triage role within the repository

B.

Users who have Read permissions within the repository

C.

Users who have Write access to the repository

D.

Users who have the security manager role within the repository​

Buy Now
Questions 20

Which top-level keys are mandatory for the dependabot.yml file? (Each answer presents part of the solution. Choose two.)

Options:

A.

updates

B.

version

C.

registries

D.

assignees

Buy Now
Questions 21

Which of the following formats are used to describe a code scanning alert from CodeQL?

Options:

A.

Common Weakness Enumeration (CWE)

B.

Vulnerability Exploitability eXchange (VEX)

C.

Common Vulnerabilities and Exposures (CVE)

D.

GitHub Security Advisory (GHSA)

Buy Now
Questions 22

Where can a user change a repository's code scanning severity threshold that fails a pull request status check?

Options:

A.

Security tab

B.

Pull Requests tab

C.

Actions tab

D.

Settings tab

Buy Now
Questions 23

Where in the repository can you give additional users access to secret scanning alerts?

Options:

A.

Security

B.

Settings

C.

Secrets

D.

Insights

Buy Now
Questions 24

When using CodeQL, how does extraction for compiled languages work?

Options:

A.

By generating one language at a time

B.

By resolving dependencies to give an accurate representation of the codebase

C.

By monitoring the normal build process

D.

By running directly on the source code

Buy Now
Questions 25

Which of the following conditions must be met to enable secret scanning for private repositories?

Options:

A.

An Advanced Security license must be uploaded to your repository.

B.

An Advanced Security license must be applied to your user account.

C.

The repository must be owned by an organization.

D.

The repository must be owned by a user account.

Buy Now
Questions 26

Which features are part of GitHub Advanced Security in the context of GitHub Enterprise? (Each correct answer presents part of the solution. Choose two.)

Options:

A.

Dependency review

B.

Dependency graph

C.

Security policy

D.

Secret scanning

Buy Now
Questions 27

Which of the following statements most accurately describes push protection for secret scanning custom patterns?​

Options:

A.

Push protection must be enabled for all, or none, of a repository's custom patterns.

B.

Push protection is an opt-in experience for each custom pattern.

C.

Push protection is not available for custom patterns.

D.

Push protection is enabled by default for new custom patterns.​

Buy Now
Questions 28

Where is secret scanning enabled on a private repository?

Options:

A.

In the code security settings

B.

Within a repository ruleset

C.

Within a secret.yml file in the repository

D.

In the code scanning default setup settings

Buy Now
Questions 29

What happens when you remove someone's access to a private repository?

Options:

A.

Local clones of the private repository are deleted.

B.

Team access to a private repository is revoked.

C.

Their forks of that private repository are deleted.

D.

Confidential information is deleted.

Buy Now
Questions 30

What does code scanning do?

Options:

A.

It contacts maintainers to ask them to create security advisories if a vulnerability is found

B.

It prevents code pushes with vulnerabilities as a pre-receive hook

C.

It analyzes a GitHub repository to find security vulnerabilities

D.

It scans your entire Git history on branches present in your GitHub repository for any secrets

Buy Now
Questions 31

By default, what is the minimum role needed to bypass push protection in a repository?

Options:

A.

Maintain

B.

Write

C.

Admin

D.

Triage

Buy Now
Questions 32

What filter or sort settings can be used to prioritize the secret scanning alerts that present the most risk?

Options:

A.

Sort to display the oldest first

B.

Sort to display the newest first

C.

Filter to display active secrets

D.

Select only the custom patterns

Buy Now
Questions 33

Which of the following would raise secret scanning alerts?

Options:

A.

GitHub personal access token

B.

Structured Query Language (SQL) injection

C.

Cross-site scripting (XSS)

D.

Server-side request forgery

Buy Now
Questions 34

If notification and alert recipients are not customized, which users receive notifications about new Dependabot alerts in an affected repository?

Options:

A.

Users with Write permissions to the repository

B.

Users with Admin privileges to the repository

C.

Users with Maintain privileges to the repository

D.

Users with Read permissions to the repository

Buy Now
Questions 35

You want to enforce an enterprise policy that allows repository administrators within all organizations to enable GitHub Advanced Security for their repositories. Which option should you choose for this policy?

Options:

A.

No policy

B.

Allow for all organizations

C.

Never allow

D.

Allow for selected organizations

Buy Now
Questions 36

Which Dependabot configuration fields are required? (Each answer presents part of the solution. Choose three.)

Options:

A.

directory

B.

package-ecosystem

C.

milestone

D.

schedule.interval

E.

allow

Buy Now
Questions 37

Where can you view code scanning results from CodeQL analysis?

Options:

A.

The repository's code scanning alerts

B.

A CodeQL database

C.

A CodeQL query pack

D.

At Security advisories

Buy Now
Exam Code: GH-500
Exam Name: GitHub Advanced Security Exam
Last Update: Oct 5, 2026
Questions: 125
GH-500 pdf

GH-500 PDF

$23.75  $94.99
GH-500 Engine

GH-500 Testing Engine

$27.5  $109.99
GH-500 PDF + Engine

GH-500 PDF + Testing Engine

$36.25  $144.99