
GitHubAdvanced Security (GH-500)
Domain 1Objective 3
Detect, Manage, and Respond to Security Alerts GH-500 Practice Questions (Page 4)
Part of the Describe GitHub Security suites, features, and ecosystem domain, which accounts for 15-20% of the GH-500 exam.
33questions here
7free pages
9concepts
15-20%of the exam
Questions 16–20
- 16
A developer is working on a critical security fix for a Dependabot alert. The fix requires updating a dependency that is used in multiple services. The developer wants to ensure the fix is safe before merging. What is the best approach?
Select an answer first - 17
A developer receives a Dependabot alert for a critical vulnerability in a production dependency. The alert shows a patched version is available, but the developer is unsure if the patch is compatible with the current codebase. What is the most appropriate first action?
Select an answer first - 18
An organization wants to ensure that only the security team can dismiss alerts, while developers can view them. What should an administrator configure?
Select an answer first - 19
A developer receives a secret scanning alert for a token that was exposed in a commit three weeks ago. The token is still active. What is the developer's primary responsibility?
Select an answer first - 20
What is the primary purpose of secret scanning in GitHub?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GitHub. “GH-500” is a trademark of its owner, used for identification only.