
GitHubAdvanced Security (GH-500)
Domain 4Objective 3
Analyze, Triage, and Remediate Code Scanning Results GH-500 Practice Questions (Page 2)
Part of the Configure and use Code Security (formerly Code Scanning with CodeQL) domain, which accounts for 10-15% of the GH-500 exam.
22questions here
5free pages
7concepts
10-15%of the exam
Questions 6–10
- 6
Which of the following is a valid reason to dismiss a code scanning alert?
Select an answer first - 7
A security team is managing a large number of code scanning alerts. They want to ensure that all high-severity alerts are remediated within a week, but the team is small and cannot fix everything at once. The team also wants to avoid alert fatigue. What is the best approach?
Select an answer first - 8
In CodeQL dataflow analysis, what does the term 'source' refer to?
Select an answer first - 9
A security team is triaging code scanning alerts and notices that many alerts are classified as 'high' severity but are actually low-risk because they are in non-critical modules. The team wants to improve triage accuracy so that high-severity alerts get the most attention. What should the team do?
Select an answer first - 10
Where can you find an autofix suggestion for a code scanning alert?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GitHub. “GH-500” is a trademark of its owner, used for identification only.