Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GitHub logo

GitHubAdvanced Security (GH-500)

Domain 1Objective 3

Detect, Manage, and Respond to Security Alerts GH-500 Practice Questions (Page 1)

Part of the Describe GitHub Security suites, features, and ecosystem domain, which accounts for 15-20% of the GH-500 exam.

33questions here
7free pages
9concepts
15-20%of the exam

Questions 1–5

  1. 1application · medium

    A Dependabot alert is created for a vulnerability in a npm package. The advisory database does not yet have a patched version. What is the most appropriate action?

    Select an answer first
  2. 2foundation · easy

    Which type of security alert is generated when GitHub detects a known vulnerable version of a dependency in a repository's manifest file?

    Select an answer first
  3. 3foundation · easy

    What is the primary source of vulnerability information that Dependabot uses to identify known vulnerabilities in dependencies?

    Select an answer first
  4. 4application · medium

    A developer notices a Dependabot alert for a vulnerability in a transitive dependency. The direct dependency is not vulnerable, but the transitive one is. What is the most accurate statement about this alert?

    Select an answer first
  5. 5expert · hard

    An organization wants to automate the remediation of Dependabot alerts by automatically creating pull requests for patched versions, but only for dependencies that are not pinned to exact versions. They also want to avoid overwhelming developers with too many PRs. Which approach best balances automation and control?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GitHub. “GH-500” is a trademark of its owner, used for identification only.