
GitHubAdvanced Security (GH-500)
Domain 1Objective 2
Apply Secure SDLC and Security Strategies GH-500 Practice Questions (Page 5)
Part of the Describe GitHub Security suites, features, and ecosystem domain, which accounts for 15-20% of the GH-500 exam.
23questions here
5free pages
4concepts
15-20%of the exam
Questions 21–23
- 21
In a secure SDLC, which GitHub feature can automatically create pull requests to update vulnerable dependencies to patched versions?
Select an answer first - 22
A developer accidentally commits an AWS access key to a feature branch and pushes it. The organization has secret scanning enabled but not push protection. What is the immediate risk and what should be done first?
Select an answer first - 23
A software company wants to enforce a gate-based security strategy at release time. They currently have code scanning, secret scanning, and Dependabot enabled. They want to ensure that no critical or high severity alerts are present when a release branch is created. Which approach best achieves this while minimizing disruption to developers?
Select an answer first
Finished these 3 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to GH-500
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GitHub. “GH-500” is a trademark of its owner, used for identification only.