Microsoft GH-500 GitHub Advanced Security Exam Exam Practice Test
GitHub Advanced Security Exam Questions and Answers
When using CodeQL, how does extraction for compiled languages work?
Which syntax in a query suite tells CodeQL to look for one or more specified .ql files?
Which of the following dependencies could trigger a Dependabot alert? (Each answer presents a complete solution. Choose two.)
As a repository owner, you want to receive specific notifications, including security alerts, for an individual repository. Which repository notification setting should you use?
What step is required to run a SARIF-compatible (Static Analysis Results Interchange Format) tool on GitHub Actions?
Which of the following steps should you follow to integrate CodeQL into a third-party continuous integration system? (Each answer presents part of the solution. Choose three.)
Which of the following Watch settings could you use to get Dependabot alert notifications? (Each answer presents part of the solution. Choose two.)
Assuming that notification and alert recipients are not customized, what does GitHub do when it identifies a vulnerable dependency in a repository where Dependabot alerts are enabled? (Each answer presents part of the solution. Choose two.)
Which of the following conditions must be met to enable secret scanning for private repositories?
You want to enforce an enterprise policy that allows repository administrators within all organizations to enable GitHub Advanced Security for their repositories. Which option should you choose for this policy?
Assuming security and analysis features are not configured at the repository, organization, or enterprise level, secret scanning is enabled on:
Which alerts do you see in the repository's Security tab? (Each answer presents part of the solution. Choose three.)
Where can you find the vulnerable dependencies that GitHub detected in your repository?
What is a prerequisite to define a custom pattern for a repository?
When secret scanning detects a set of credentials on a public repository, what does GitHub do?
What does a CodeQL database of your repository contain?
By default, where will secret scanning look in a repository in order to execute its job? (Each correct answer presents part of the solution. Choose three.)
When using the advanced CodeQL code scanning setup, what is the name of the workflow file?
If default code security settings have not been changed at the repository, organization, or enterprise level, which repositories receive Dependabot alerts?
As a repository owner, you do not want to run a GitHub Actions workflow when changes are made to any .txt or markdown files. How would you adjust the event trigger for a pull request that targets the main branch? (Each answer presents part of the solution. Choose three.)
on:
pull_request:
branches: [main]
Which features are part of GitHub Advanced Security in the context of GitHub Enterprise? (Each correct answer presents part of the solution. Choose two.)
As a developer with write access, you navigate to a code scanning alert in your repository. When will GitHub close this alert?
Which of the following formats are used to describe a Dependabot alert? (Each answer presents a complete solution. Choose two.)
What classifications are used to categorize Dependabot alerts? (Each correct answer presents part of the solution. Choose three.)
You want to specify a CodeQL configuration file for a GitHub Actions workflow. Which input to the init step in the CodeQL action do you use to pass the path of the configuration file?
As a developer, you need to configure a code scanning workflow for a repository where GitHub Advanced Security is enabled. What minimum repository permission do you need?
By default, what is the minimum role needed to bypass push protection in a repository?
Your security team requested that you enable the dependency graph. What happens when you enable this feature for your repository?
What happens when you remove someone's access to a private repository?
What are Dependabot security updates?
What permission level is required to manage code scanning alerts in a repository?
You are a maintainer of a repository and Dependabot notifies you of a vulnerability. Where could the vulnerability have been disclosed? (Each answer presents part of the solution. Choose two.)
A repository's dependency graph includes:
Where is secret scanning enabled on a private repository?
Which security feature shows a vulnerable dependency in a pull request?
Which of the following options would close a Dependabot alert?
Which CodeQL query suite provides queries of lower severity than the default query suite?