
GitHubAdvanced Security (GH-500)
Domain 3Objective 4
Configure Policies, Permissions, and Integrations GH-500 Practice Questions (Page 3)
Part of the Configure and use supply chain security (formerly Dependabot/Dependency Review) domain, which accounts for 15-20% of the GH-500 exam.
25questions here
5free pages
7concepts
15-20%of the exam
Questions 11–15
- 11
What is the primary function of Dependabot version updates?
Select an answer first - 12
You need to send security alert events to an internal SIEM system for monitoring. The SIEM expects to receive events via a specific endpoint. What should you configure in GitHub to achieve this?
Select an answer first - 13
Your organization uses a third-party code scanning tool that is not a GitHub Action. You want to integrate its results into GitHub Advanced Security. What is the most appropriate way to do this?
Select an answer first - 14
Your organization uses GitHub Advanced Security. The security team wants secret scanning alerts for the `prod-config` repository to be triaged by the DevOps team, while dependency vulnerabilities should be handled by the application security team. Both teams need to see the alerts, but only the assigned team should be able to change the alert state. What should you configure?
Select an answer first - 15
Your organization wants to generate an SBOM for each release of your software. You are using GitHub Actions for your CI/CD. What is the most efficient way to generate and publish an SBOM?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GitHub. “GH-500” is a trademark of its owner, used for identification only.