As a repository owner, you want to receive specific notifications, including security alerts, for an individual repository. Which repository notification setting should you use?
Assuming there is no custom Dependabot behavior configured, where possible, what does Dependabot do after sending an alert about a vulnerable dependency in a repository?
When using code scanning and GitHub Actions on Windows, what is the relative difference between the minute consumption of code scanning jobs and jobs on Linux runners?
Which of the following steps should you follow to integrate CodeQL into a third-party continuous integration system? (Each answer presents part of the solution. Choose three.)
What step is required to run a SARIF-compatible (Static Analysis Results Interchange Format) tool on GitHub Actions?
Which of the following dependencies could trigger a Dependabot alert? (Each answer presents a complete solution. Choose two.)
Assuming that default security and analysis settings have not been changed at the repository, organization, or enterprise level, which scenario would generate a dependency graph for the repository?
What do you need to do before you can define a custom pattern for a repository?
In a private repository, what minimum requirements does GitHub need to generate a dependency graph? (Each answer presents part of the solution. Choose two.)
Which details do you have to provide to create a custom pattern for secret scanning? (Each answer presents part of the solution. Choose two.)
You need to run code scanning when files are modified in a specific directory. Which option can be used to complete line 3 in the workflow fragment below?
1. on:
2. push:
3.
Which top-level keys are mandatory for the dependabot.yml file? (Each answer presents part of the solution. Choose two.)
Which of the following formats are used to describe a code scanning alert from CodeQL?
Where can a user change a repository's code scanning severity threshold that fails a pull request status check?
Where in the repository can you give additional users access to secret scanning alerts?
Which of the following conditions must be met to enable secret scanning for private repositories?
Which features are part of GitHub Advanced Security in the context of GitHub Enterprise? (Each correct answer presents part of the solution. Choose two.)
Which of the following statements most accurately describes push protection for secret scanning custom patterns?
By default, what is the minimum role needed to bypass push protection in a repository?
What filter or sort settings can be used to prioritize the secret scanning alerts that present the most risk?
If notification and alert recipients are not customized, which users receive notifications about new Dependabot alerts in an affected repository?
You want to enforce an enterprise policy that allows repository administrators within all organizations to enable GitHub Advanced Security for their repositories. Which option should you choose for this policy?
Which Dependabot configuration fields are required? (Each answer presents part of the solution. Choose three.)