Weekend Sale Special - 75% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 75only

GH-500 GitHub Advanced Security Exam Questions and Answers

Questions 4

What classifications are used to categorize Dependabot alerts? (Each correct answer presents part of the solution. Choose three.)

Options:

A.

Static Application Security Testing (SAST)

B.

Exploit Prediction Scoring System (EPSS)

C.

Common Vulnerabilities and Exposures (CVE)

D.

GitHub Security Advisory ID (GHSA)

E.

Common Weakness Enumeration (CWE)

Buy Now
Questions 5

If notification and alert recipients are not customized, which users receive notifications about new Dependabot alerts in an affected repository?

Options:

A.

Users with Write permissions to the repository

B.

Users with Admin privileges to the repository

C.

Users with Maintain privileges to the repository

D.

Users with Read permissions to the repository

Buy Now
Questions 6

Who can fix a code scanning alert on a private repository?​

Options:

A.

Users who have the Triage role within the repository

B.

Users who have Read permissions within the repository

C.

Users who have Write access to the repository

D.

Users who have the security manager role within the repository​

Buy Now
Questions 7

Which alerts do you see in the repository's Security tab? (Each answer presents part of the solution. Choose three.)

Options:

A.

Repository permissions

B.

Secret scanning alerts

C.

Dependabot alerts

D.

Security status alerts

E.

Code scanning alerts

Buy Now
Questions 8

Which details do you have to provide to create a custom pattern for secret scanning? (Each answer presents part of the solution. Choose two.)

Options:

A.

The secret format

B.

The name of the pattern

C.

A list of repositories to scan

D.

Additional match requirements for the secret format

Buy Now
Questions 9

Where in the repository can you give additional users access to secret scanning alerts?

Options:

A.

Security

B.

Settings

C.

Secrets

D.

Insights

Buy Now
Questions 10

What is the first step you should take to fix an alert in secret scanning?

Options:

A.

Archive the repository.

B.

Update your dependencies.

C.

Revoke the alert if the secret is still valid.

D.

Remove the secret in a commit to the main branch.

Buy Now
Questions 11

By default, where will secret scanning look in a repository in order to execute its job? (Each correct answer presents part of the solution. Choose three.)

Options:

A.

Dependencies

B.

Selected files in the repository

C.

All branches

D.

Full commit history

E.

All files in the repository

Buy Now
Questions 12

Where can you find the vulnerable dependencies that GitHub detected in your repository?

Options:

A.

In Dependabot alerts

B.

In secret scanning alerts

C.

In security advisories

D.

In code scanning alerts

Buy Now
Questions 13

As a developer, you need to configure a code scanning workflow for a repository where GitHub Advanced Security is enabled. What minimum repository permission do you need?

Options:

A.

Write

B.

None

C.

Admin

D.

Read

Buy Now
Questions 14

Which of the following dependencies could trigger a Dependabot alert? (Each answer presents a complete solution. Choose two.)

Options:

A.

Indirect dependencies explicitly declared in a lockfile

B.

Loose dependencies declared in a manifest

C.

Direct dependencies explicitly declared in a manifest

D.

Direct dependencies at 08:00 UTC

Buy Now
Questions 15

You need to run code scanning when files are modified in a specific directory. Which option can be used to complete line 3 in the workflow fragment below?

1. on:

2. push:

3.

Options:

A.

**foo

B.

(

C.

?

D.

paths:

Buy Now
Questions 16

As a repository owner, you want to receive specific notifications, including security alerts, for an individual repository. Which repository notification setting should you use?

Options:

A.

Ignore

B.

Participating and @mentions

C.

All Activity

D.

Custom

Buy Now
Questions 17

When using the advanced CodeQL code scanning setup, what is the name of the workflow file?​

Options:

A.

codeql-config.yml

B.

codeql-scan.yml

C.

codeql-workflow.yml

D.

codeql-analysis.yml

Buy Now
Questions 18

When configuring code scanning with CodeQL, what are your options for specifying additional queries? (Each answer presents part of the solution. Choose two.)

Options:

A.

Packs

B.

github/codeql

C.

Scope

D.

Queries

Buy Now
Questions 19

Secret scanning will ignore a secret_scanning.yml file that:

Options:

A.

Is 100 KB or larger.

B.

Is 1 MB or larger.

C.

Contains 1,000 or more entries.

D.

Has 1,000 or more directories.

Buy Now
Questions 20

What happens when you enable secret scanning on a private repository?

Options:

A.

Repository administrators can view Dependabot alerts.

B.

Your team is subscribed to security alerts.

C.

GitHub performs a read-only analysis on the repository.

D.

Dependency review, secret scanning, and code scanning are enabled.

Buy Now
Questions 21

Assuming there is no custom Dependabot behavior configured, where possible, what does Dependabot do after sending an alert about a vulnerable dependency in a repository?

Options:

A.

Creates a pull request to upgrade the vulnerable dependency to the minimum possible secure version

B.

Scans repositories for vulnerable dependencies on a schedule and adds those files to a manifest

C.

Constructs a graph of all the repository's dependencies and public dependents for the default branch

D.

Scans any push to all branches and generates an alert for each vulnerable repository

Buy Now
Questions 22

Which of the following features helps to prioritize secret scanning alerts that present an immediate risk?

Options:

A.

Non-provider patterns

B.

Push protection

C.

Custom pattern dry runs

D.

Secret validation

Buy Now
Questions 23

Which security feature shows a vulnerable dependency in a pull request?

Options:

A.

Dependency graph

B.

Dependency review

C.

Dependabot alert

D.

The repository's Security tab

Buy Now
Questions 24

Where can you view code scanning results from CodeQL analysis?

Options:

A.

The repository's code scanning alerts

B.

A CodeQL database

C.

A CodeQL query pack

D.

At Security advisories

Buy Now
Questions 25

Which of the following is the best way to prevent developers from adding secrets to the repository?

Options:

A.

Create a CODEOWNERS file

B.

Make the repository public

C.

Configure a security manager

D.

Enable push protection

Buy Now
Questions 26

In a private repository, what minimum requirements does GitHub need to generate a dependency graph? (Each answer presents part of the solution. Choose two.)​

Options:

A.

Read-only access to all the repository's files

B.

Dependency graph enabled at the organization level for all new private repositories

C.

Write access to the dependency manifest and lock files for an enterprise

D.

Read-only access to the dependency manifest and lock files for a repository​

Buy Now
Questions 27

You are configuring code scanning with CodeQL. What is one impact of using a language matrix in your workflow?

Options:

A.

CodeQL excludes alerts for those dependencies specified in the language matrix.

B.

CodeQL is configured to run analysis sequentially.

C.

You can use the languages parameter under the init action.

D.

CodeQL will only analyze the languages in the matrix.

Buy Now
Questions 28

You are managing code scanning alerts for your repository. You receive an alert highlighting a problem with data flow. What do you click for additional context on the alert?​

Options:

A.

Show paths

B.

Security

C.

Code scanning alerts​

Buy Now
Questions 29

What does a CodeQL database of your repository contain?​

Options:

A.

A build for Go projects to set up the project

B.

A build of the code and extracted data

C.

Build commands for C/C++, C#, and Java

D.

A representation of all of the source code​

GitHub

Agentic AI for AppSec Teams

Buy Now
Questions 30

Which of the following options would close a Dependabot alert?

Options:

A.

Creating a pull request to resolve the vulnerability that will be approved and merged

B.

Viewing the Dependabot alert on the Dependabot alerts tab of your repository

C.

Viewing the dependency graph

D.

Leaving the repository in its current state

Buy Now
Questions 31

What are Dependabot security updates?

Options:

A.

Automated pull requests that help you update dependencies that have known vulnerabilities

B.

Automated pull requests that keep your dependencies updated, even when they don’t have any vulnerabilities

C.

Automated pull requests to update the manifest to the latest version of the dependency

D.

Compatibility scores to let you know whether updating a dependency could cause breaking changes to your project

Buy Now
Questions 32

Which of the following is the most complete method for Dependabot to find vulnerabilities in third-party dependencies?

Options:

A.

Dependabot reviews manifest files in the repository

B.

CodeQL analyzes the code and raises vulnerabilities in third-party dependencies

C.

A dependency graph is created, and Dependabot compares the graph to the GitHub Advisory database

D.

The build tool finds the vulnerable dependencies and calls the Dependabot API

Buy Now
Questions 33

Assuming that no custom Dependabot behavior is configured, who has the ability to merge a pull request created via Dependabot security updates?​

Options:

A.

An enterprise administrator

B.

A user who has write access to the repository

C.

A user who has read access to the repository

D.

A repository member of an enterprise organization​

Buy Now
Questions 34

As a repository owner, you do not want to run a GitHub Actions workflow when changes are made to any .txt or markdown files. How would you adjust the event trigger for a pull request that targets the main branch? (Each answer presents part of the solution. Choose three.)

    on:

    pull_request:

    branches: [main]

Options:

A.

- '/*.md'

B.

- '/*.txt'

C.

paths:

D.

paths-ignore:

E.

- 'docs/*.md'

Buy Now
Questions 35

The autobuild step in the CodeQL workflow has failed. What should you do?

Options:

A.

Remove specific build steps.

B.

Compile the source code.

C.

Remove the autobuild step from your code scanning workflow and add specific build steps.

D.

Use CodeQL, which implicitly detects the supported languages in your code base.

Buy Now
Questions 36

Which of the following statements most accurately describes push protection for secret scanning custom patterns?​

Options:

A.

Push protection must be enabled for all, or none, of a repository's custom patterns.

B.

Push protection is an opt-in experience for each custom pattern.

C.

Push protection is not available for custom patterns.

D.

Push protection is enabled by default for new custom patterns.​

Buy Now
Questions 37

Which of the following options are code scanning application programming interface (API) endpoints? (Each answer presents part of the solution. Choose two.)

Options:

A.

List all open code scanning alerts for the default branch

B.

Modify the severity of an open code scanning alert

C.

Get a single code scanning alert

D.

Delete all open code scanning alerts

Buy Now
Exam Code: GH-500
Exam Name: GitHub Advanced Security Exam
Last Update: Oct 4, 2026
Questions: 125

PDF + Testing Engine

$43.75  $174.99

Testing Engine

$33.75  $134.99
buy now GH-500 testing engine

PDF (Q&A)

$28.75  $114.99
buy now GH-500 pdf
dumpsmate guaranteed to pass

24/7 Customer Support

DumpsMate's team of experts is always available to respond your queries on exam preparation. Get professional answers on any topic of the certification syllabus. Our experts will thoroughly satisfy you.

Site Secure

mcafee secure

TESTED 04 Oct 2026