
GitHubAdvanced Security (GH-500)
Domain 5Objective 3
Customize and Optimize Security Detection GH-500 Practice Questions (Page 2)
Part of the Security operations: best practices, prioritization, and remediation domain, which accounts for 15-20% of the GH-500 exam.
21questions here
5free pages
6concepts
15-20%of the exam
Questions 6–10
- 6
A security team receives a large number of CodeQL alerts from a recent scan. They need to prioritize which alerts to remediate first. They have limited resources and want to focus on the most critical vulnerabilities. Which factor should they consider FIRST when prioritizing alerts?
Select an answer first - 7
A team wants to run CodeQL on a TypeScript repository. They want to include only queries that are relevant to their risk profile, which includes SQL injection and XSS. They also want to exclude queries that are not relevant to their web application. What should they do?
Select an answer first - 8
Which of the following is an example of integrating remediation workflows with security detection?
Select an answer first - 9
A company wants to ensure that CodeQL alerts are not only detected but also resolved in a timely manner. They want to automate the process of creating issues for alerts and assigning them to the responsible developers. What GitHub feature should they use?
Select an answer first - 10
What is the primary purpose of a CodeQL query suite?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GitHub. “GH-500” is a trademark of its owner, used for identification only.