
GitHubAdvanced Security (GH-500)
Domain 5Objective 4
Collaborate Across Roles and Enforce Governance GH-500 Practice Questions (Page 1)
Part of the Security operations: best practices, prioritization, and remediation domain, which accounts for 15-20% of the GH-500 exam.
28questions here
6free pages
8concepts
15-20%of the exam
Questions 1–5
- 1
Your organization has a mix of repositories: some are internal, some are public, and some are for customers. You need to enforce different security policies for each type. For example, public repositories must have secret scanning and code scanning enabled, while internal repositories only require secret scanning. What is the most efficient way to manage this?
Select an answer first - 2
Your organization has a GitHub Enterprise Cloud plan with Advanced Security enabled. The security team needs to triage code scanning alerts, but they should not be able to modify repository settings or manage the Advanced Security feature itself. Which role should you assign to the security team members?
Select an answer first - 3
Your organization is preparing for a SOC 2 audit. The auditor requires evidence that security policies are enforced and that exceptions are documented. You have a mix of repositories, some with legacy code that cannot easily be fixed. What is the best approach to satisfy the auditor?
Select an answer first - 4
Which GitHub feature allows you to create a ruleset that applies to all repositories in an organization?
Select an answer first - 5
Your organization requires that all code changes pass a security scanning job before they can be merged into the main branch. You need to enforce this requirement. What should you configure?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GitHub. “GH-500” is a trademark of its owner, used for identification only.