
GitHubAdvanced Security (GH-500)
Domain 1Objective 3
Detect, Manage, and Respond to Security Alerts GH-500 Practice Questions (Page 6)
Part of the Describe GitHub Security suites, features, and ecosystem domain, which accounts for 15-20% of the GH-500 exam.
33questions here
7free pages
9concepts
15-20%of the exam
Questions 26–30
- 26
A security analyst finds a Dependabot alert for a vulnerability in a dependency that is no longer used in the codebase. The dependency is still listed in the package manifest. What is the best action?
Select an answer first - 27
A developer receives a secret scanning alert for a GitHub personal access token (PAT) that was exposed in a commit. The PAT has been revoked. What should the developer do with the alert?
Select an answer first - 28
A security team wants to receive notifications in a Slack channel whenever a new code scanning alert is opened in any repository. Which approach should they use?
Select an answer first - 29
What is the recommended practice when dismissing a security alert?
Select an answer first - 30
Which of the following is a valid way to filter security alerts in the GitHub UI?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GitHub. “GH-500” is a trademark of its owner, used for identification only.