Pre-Winter Sale Limited Time Flat 70% Discount offer - Ends in 0d 00h 00m 00s - Coupon code: 70spcl

Microsoft GH-500 GitHub Advanced Security Exam Exam Practice Test

Page: 1 / 13
Total 125 questions

GitHub Advanced Security Exam Questions and Answers

Question 1

When using CodeQL, how does extraction for compiled languages work?

Options:

A.

By generating one language at a time

B.

By resolving dependencies to give an accurate representation of the codebase

C.

By monitoring the normal build process

D.

By running directly on the source code

Question 2

Which syntax in a query suite tells CodeQL to look for one or more specified .ql files?

Options:

A.

query

B.

qlpack

C.

qls

Question 3

Which of the following dependencies could trigger a Dependabot alert? (Each answer presents a complete solution. Choose two.)

Options:

A.

Indirect dependencies explicitly declared in a lockfile

B.

Loose dependencies declared in a manifest

C.

Direct dependencies explicitly declared in a manifest

D.

Direct dependencies at 08:00 UTC

Question 4

As a repository owner, you want to receive specific notifications, including security alerts, for an individual repository. Which repository notification setting should you use?

Options:

A.

Ignore

B.

Participating and @mentions

C.

All Activity

D.

Custom

Question 5

What step is required to run a SARIF-compatible (Static Analysis Results Interchange Format) tool on GitHub Actions?​

Options:

A.

Update the workflow to include a final step that uploads the results.

B.

By default, the CodeQL runner automatically uploads results to GitHub on completion.

C.

The CodeQL action uploads the SARIF file automatically when it completes analysis.

D.

Use the CLI to upload results to GitHub.​

Question 6

Which of the following steps should you follow to integrate CodeQL into a third-party continuous integration system? (Each answer presents part of the solution. Choose three.)

Options:

A.

Process alerts

B.

Analyze code

C.

Upload scan results

D.

Install the CLI

E.

Write queries

Question 7

Which of the following Watch settings could you use to get Dependabot alert notifications? (Each answer presents part of the solution. Choose two.)

Options:

A.

The Custom setting

B.

The Participating and @mentions setting

C.

The All Activity setting

D.

The Ignore setting

Question 8

Assuming that notification and alert recipients are not customized, what does GitHub do when it identifies a vulnerable dependency in a repository where Dependabot alerts are enabled? (Each answer presents part of the solution. Choose two.)​

Options:

A.

It generates a Dependabot alert and displays it on the Security tab for the repository.

B.

It notifies the repository administrators about the new alert.

C.

It generates Dependabot alerts by default for all private repositories.

D.

It consults with a security service and conducts a thorough vulnerability review.​

Question 9

Which of the following conditions must be met to enable secret scanning for private repositories?

Options:

A.

An Advanced Security license must be uploaded to your repository.

B.

An Advanced Security license must be applied to your user account.

C.

The repository must be owned by an organization.

D.

The repository must be owned by a user account.

Question 10

You want to enforce an enterprise policy that allows repository administrators within all organizations to enable GitHub Advanced Security for their repositories. Which option should you choose for this policy?

Options:

A.

No policy

B.

Allow for all organizations

C.

Never allow

D.

Allow for selected organizations

Question 11

Assuming security and analysis features are not configured at the repository, organization, or enterprise level, secret scanning is enabled on:

Options:

A.

Public repositories

B.

All new repositories within your organization

C.

User-owned private repositories

D.

Private repositories

Question 12

Which alerts do you see in the repository's Security tab? (Each answer presents part of the solution. Choose three.)

Options:

A.

Repository permissions

B.

Secret scanning alerts

C.

Dependabot alerts

D.

Security status alerts

E.

Code scanning alerts

Question 13

Where can you find the vulnerable dependencies that GitHub detected in your repository?

Options:

A.

In Dependabot alerts

B.

In secret scanning alerts

C.

In security advisories

D.

In code scanning alerts

Question 14

What is a prerequisite to define a custom pattern for a repository?

Options:

A.

Change the repository visibility to Internal

B.

Close other secret scanning alerts

C.

Specify additional match criteria

D.

Enable secret scanning

Question 15

When secret scanning detects a set of credentials on a public repository, what does GitHub do?

Options:

A.

It notifies the service provider who issued the secret.

B.

It displays a public alert in the Security tab of the repository.

C.

It scans the contents of the commits for additional secrets.

D.

It sends a notification to repository members.

Question 16

What does a CodeQL database of your repository contain?​

Options:

A.

A build for Go projects to set up the project

B.

A build of the code and extracted data

C.

Build commands for C/C++, C#, and Java

D.

A representation of all of the source code​

GitHub

Agentic AI for AppSec Teams

Question 17

By default, where will secret scanning look in a repository in order to execute its job? (Each correct answer presents part of the solution. Choose three.)

Options:

A.

Dependencies

B.

Selected files in the repository

C.

All branches

D.

Full commit history

E.

All files in the repository

Question 18

When using the advanced CodeQL code scanning setup, what is the name of the workflow file?​

Options:

A.

codeql-config.yml

B.

codeql-scan.yml

C.

codeql-workflow.yml

D.

codeql-analysis.yml

Question 19

If default code security settings have not been changed at the repository, organization, or enterprise level, which repositories receive Dependabot alerts?

Options:

A.

Repositories owned by an enterprise account

B.

Private repositories

C.

None

D.

Repositories owned by an organization

Question 20

As a repository owner, you do not want to run a GitHub Actions workflow when changes are made to any .txt or markdown files. How would you adjust the event trigger for a pull request that targets the main branch? (Each answer presents part of the solution. Choose three.)

    on:

    pull_request:

    branches: [main]

Options:

A.

- '/*.md'

B.

- '/*.txt'

C.

paths:

D.

paths-ignore:

E.

- 'docs/*.md'

Question 21

Which features are part of GitHub Advanced Security in the context of GitHub Enterprise? (Each correct answer presents part of the solution. Choose two.)

Options:

A.

Dependency review

B.

Dependency graph

C.

Security policy

D.

Secret scanning

Question 22

As a developer with write access, you navigate to a code scanning alert in your repository. When will GitHub close this alert?

Options:

A.

After you triage the pull request containing the alert

B.

When you use data-flow analysis to find potential security issues in code

C.

After you find the code and click the alert within the pull request

D.

After you fix the code by committing within the pull request

Question 23

Which of the following formats are used to describe a Dependabot alert? (Each answer presents a complete solution. Choose two.)​

Options:

A.

Common Weakness Enumeration (CWE)

B.

Exploit Prediction Scoring System (EPSS)

C.

Common Vulnerabilities and Exposures (CVE)

D.

Vulnerability Exploitability exchange (VEX)​

Question 24

What classifications are used to categorize Dependabot alerts? (Each correct answer presents part of the solution. Choose three.)

Options:

A.

Static Application Security Testing (SAST)

B.

Exploit Prediction Scoring System (EPSS)

C.

Common Vulnerabilities and Exposures (CVE)

D.

GitHub Security Advisory ID (GHSA)

E.

Common Weakness Enumeration (CWE)

Question 25

You want to specify a CodeQL configuration file for a GitHub Actions workflow. Which input to the init step in the CodeQL action do you use to pass the path of the configuration file?

Options:

A.

config-file

B.

source-root

C.

db-location

D.

queries

Question 26

As a developer, you need to configure a code scanning workflow for a repository where GitHub Advanced Security is enabled. What minimum repository permission do you need?

Options:

A.

Write

B.

None

C.

Admin

D.

Read

Question 27

By default, what is the minimum role needed to bypass push protection in a repository?

Options:

A.

Maintain

B.

Write

C.

Admin

D.

Triage

Question 28

Your security team requested that you enable the dependency graph. What happens when you enable this feature for your repository?

Options:

A.

Admins of the repository will see dependency information in the dependency graph.

B.

Dependabot security updates create pull requests to upgrade those dependencies.

C.

New repositories will need to have dependency information enabled.

D.

GitHub generates Dependabot alerts for vulnerable dependencies.

Question 29

What happens when you remove someone's access to a private repository?

Options:

A.

Local clones of the private repository are deleted.

B.

Team access to a private repository is revoked.

C.

Their forks of that private repository are deleted.

D.

Confidential information is deleted.

Question 30

What are Dependabot security updates?

Options:

A.

Automated pull requests that help you update dependencies that have known vulnerabilities

B.

Automated pull requests that keep your dependencies updated, even when they don’t have any vulnerabilities

C.

Automated pull requests to update the manifest to the latest version of the dependency

D.

Compatibility scores to let you know whether updating a dependency could cause breaking changes to your project

Question 31

What permission level is required to manage code scanning alerts in a repository?

Options:

A.

Read

B.

Maintain

C.

View

D.

Triage

Question 32

You are a maintainer of a repository and Dependabot notifies you of a vulnerability. Where could the vulnerability have been disclosed? (Each answer presents part of the solution. Choose two.)​

Options:

A.

In the National Vulnerability Database

B.

In the dependency graph

C.

In security advisories reported on GitHub

D.

In manifest and lock files

Question 33

A repository's dependency graph includes:

Options:

A.

Dependencies parsed from a repository's manifest and lock files.

B.

Annotated code scanning alerts from your repository's dependencies.

C.

A summary of the dependencies used in your organization's repositories.

D.

Dependencies from all your repositories.

Question 34

Where is secret scanning enabled on a private repository?

Options:

A.

In the code security settings

B.

Within a repository ruleset

C.

Within a secret.yml file in the repository

D.

In the code scanning default setup settings

Question 35

Which security feature shows a vulnerable dependency in a pull request?

Options:

A.

Dependency graph

B.

Dependency review

C.

Dependabot alert

D.

The repository's Security tab

Question 36

Which of the following options would close a Dependabot alert?

Options:

A.

Creating a pull request to resolve the vulnerability that will be approved and merged

B.

Viewing the Dependabot alert on the Dependabot alerts tab of your repository

C.

Viewing the dependency graph

D.

Leaving the repository in its current state

Question 37

Which CodeQL query suite provides queries of lower severity than the default query suite?

Options:

A.

github/codeql-go/ql/src@main

B.

github/codeql/cpp/ql/src@main

C.

security-extended

Page: 1 / 13
Total 125 questions