Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GITHUB

GitHub Advanced Security (GH-500)

GH-500GitHub Advanced Security Certification

The GitHub Advanced Security certification validates your expertise in securing code and workflows with GitHub's advanced security features. Designed for security professionals and developers, this certification demonstrates your ability to identify vulnerabilities, implement security controls, and protect the software supply chain. Earning it signals that you can proactively harden GitHub environments against evolving threats.

537 practice questions · Updated 2026-07-30

6Domains
25Objectives
158Concepts
537Questions

GH-500 Curriculum

Every domain, objective, and concept the GH-500 exam measures.

  1. GitHub Security suite structure
  2. Navigation of security features
  3. Code Security features
  4. Secret Protection features
  5. Supply Chain Security features
  6. Contrasting security suites
  7. Public repository security features
  8. Enterprise security features
  9. Security Overview features
  10. Benefits of Security Overview
  1. Secret Protection vs. Code Security
  2. End-to-End Secure SDLC with GitHub Security Suites
  3. Prevention-First vs. Gate-Based Security Strategies
  4. Security Campaigns for Risk Reduction
  1. Vulnerability detection mechanisms
  2. Secret detection mechanisms
  3. Alert types and sources
  4. Alert management and triage
  5. Alert policies and workflows
  6. Ignoring and dismissing alerts
  7. Developer responsibilities for alerts
  8. Security team responsibilities for alerts
  9. Admin responsibilities for alerts
  1. Alert access management
  2. Roles in security alert management
  3. Delegated bypass
  4. Enforcement of security policies
  5. Supply chain security concepts
  6. Alert information across the SDLC

Enable and configure Secret Protection

6 concepts · 16 questions
  1. Enable Secret Protection at repository level
  2. Enable Secret Protection at organization level
  3. Configure Secret Protection settings
  4. Understand feature availability
  5. Contrast behavior for public repositories
  6. Contrast behavior for private and enterprise repositories

Prevent secret exposure

7 concepts · 25 questions
  1. Push Protection overview
  2. Push Protection enforcement
  3. Secret types covered by Push Protection
  4. User experience during a blocked push
  5. Bypassing Push Protection
  6. Validity checks for secrets
  7. Prioritized alerting for high-confidence secrets
  1. Secret Protection alert lifecycle
  2. Alert statuses and transitions
  3. Responding to secret alerts
  4. Dismissing alerts
  5. Best practices for alert triage
  6. Ignoring alerts and false positives
  1. Role-based bypass policies
  2. Delegated bypass policies
  3. Alert recipients configuration
  4. Alert exclusions
  5. Custom secret pattern creation
  6. Custom secret pattern management

  1. Comprehensive dependency security overview
  2. Dependency graph generation
  3. Dependency graph interpretation
  4. SBOM export options
  5. SBOM formats and supply chain context
  1. Understanding supply chain alerts
  2. Prioritizing alerts with EPSS scoring
  3. Applying security updates
  4. Remediating alerts via campaigns
  5. Remediating alerts via pull requests
  6. Configuring auto-dismiss behavior
  7. Configuring security campaigns

Secure dependencies during development

10 concepts · 27 questions
  1. Dependency Review overview
  2. Enabling Dependency Review
  3. Interpreting Dependency Review results
  4. Configuring Dependency Review
  5. License and compliance validation
  6. Dependency Review API and automation
  7. Dependency update grouping
  8. Auto-dismissing Dependabot alerts
  9. Update strategies for Dependabot
  10. Managing Dependabot pull requests
  1. Role-based alert assignment
  2. Permissions for security features
  3. Dependency update workflows
  4. Supply chain security workflows
  5. External notifications configuration
  6. Webhook setup for security events
  7. Security integrations

  1. Native code scanning options
  2. Third-party code scanning tools
  3. CodeQL vs. third-party tools selection
  4. SARIF file structure and ingestion
  5. SARIF management and interoperability

Set up and configure Code Security

6 concepts · 24 questions
  1. Enabling Code Security via GitHub Actions
  2. Enabling Code Security via External CI
  3. Configuring Code Scanning Workflows
  4. Using Workflow Templates
  5. Using Matrix Builds
  6. Defining Scan Frequency
  1. Reviewing code scanning results
  2. Understanding dataflow analysis insights
  3. Understanding alert lifecycles
  4. Using autofix capabilities
  5. Applying remediation workflows
  6. Dismissing alerts
  7. Managing severity and category classifications
  1. Advanced CodeQL configuration
  2. Customizing CodeQL analysis
  3. Automating Code Security workflows
  4. Troubleshooting scan failures
  5. Performance optimization for CodeQL scans

  1. CVE basics
  2. CWE basics
  3. GitHub Security Advisory structure
  4. Advisory-to-alert linkage
  5. End-to-end remediation workflow
  6. Prioritization criteria
  7. Remediation strategies
  8. Verification and follow-up
  1. Severity and remediation rulesets
  2. Campaign-based remediation strategies
  3. Bulk alert management
  4. Automated alert dismissal
  5. Documentation practices for alert handling
  1. CodeQL query suites
  2. Custom query suite creation
  3. Language-specific analysis configuration
  4. Risk-based detection tailoring
  5. Prioritization of security findings
  6. Remediation workflow integration
  1. Security roles and permissions
  2. Delegated exceptions
  3. Alert ownership
  4. Collaborating on alerts
  5. Security campaigns
  6. Cross-suite rulesets
  7. Policy enforcement mechanisms
  8. Governance and compliance
  1. Push protection
  2. Dependency scanning
  3. Pre-merge analysis

  1. Enterprise-level enablement
  2. Organization-level enablement
  3. Repository-level enablement
  4. Feature availability on GHEC
  5. Feature availability on GHES
  6. GHEC vs GHES feature comparison
  1. Enable Code Security (CodeQL)
  2. Enable Secret Protection
  3. Enable Supply Chain Security
  4. Define Default Configurations
  5. Understand Inheritance Behavior
  1. Enterprise and organization security policies
  2. Rulesets and enforcement boundaries
  3. Security roles and permissions
  4. CodeQL workflow configuration
  5. APIs and automation for security governance

Manage CodeQL and security automation

6 concepts · 19 questions
  1. Default CodeQL workflow setup
  2. Custom CodeQL workflow configuration
  3. Approved custom workflows governance
  4. CodeQL workflow enablement at scale
  5. Security configuration APIs
  6. Automation methods for governance
Ready to practice?Test your knowledge with exam-style questions or take an intelligent quiz tailored to your level.

Percentages reflect share of the current practice bank, not official exam weightings — no structured per-skill weight is published for GH-500, so none is invented.