
GitHubAdvanced Security (GH-500)
Domain 3Objective 4
Configure Policies, Permissions, and Integrations GH-500 Practice Questions (Page 5)
Part of the Configure and use supply chain security (formerly Dependabot/Dependency Review) domain, which accounts for 15-20% of the GH-500 exam.
25questions here
5free pages
7concepts
15-20%of the exam
Questions 21–25
- 21
Your organization wants to enforce a policy that all pull requests must include a dependency review check and an SBOM must be generated for every release. You also want to send a notification to a compliance team when a release is published. What is the most efficient way to implement this?
Select an answer first - 22
Which file is used to configure Dependabot version updates for a repository?
Select an answer first - 23
Which GitHub feature allows you to assign a security alert to a team that is responsible for a specific codebase?
Select an answer first - 24
Your organization uses a third-party tool that generates a Software Bill of Materials (SBOM) in SPDX format. You want to automatically upload this SBOM to GitHub for each release. What is the most efficient way to achieve this?
Select an answer first - 25
Your team wants Dependabot to create pull requests for dependency updates, but only for security-related updates. What is the best way to configure this?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to GH-500
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GitHub. “GH-500” is a trademark of its owner, used for identification only.