Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GitHub logo

GitHubAdvanced Security (GH-500)

Domain 3Objective 2

Detect, Prioritize, and Respond to Supply Chain Alerts GH-500 Practice Questions (Page 2)

Part of the Configure and use supply chain security (formerly Dependabot/Dependency Review) domain, which accounts for 15-20% of the GH-500 exam.

27questions here
6free pages
7concepts
15-20%of the exam

Questions 6–10

  1. 6foundation · easy

    What is the purpose of a security campaign in GitHub?

    Select an answer first
  2. 7foundation · easy

    Which type of supply chain alert in GitHub is specifically designed to notify you when a known vulnerability is detected in a dependency of your repository?

    Select an answer first
  3. 8foundation · easy

    What should you do after reviewing a Dependabot pull request that fixes a vulnerable dependency?

    Select an answer first
  4. 9expert · hard

    A security team is planning a security campaign to remediate a critical vulnerability in a library used by several repositories. Some repositories have strict change-management processes that require manual approval, while others allow automated merging. The team wants to ensure the campaign progresses efficiently without violating change-management policies. What should they do?

    Select an answer first
  5. 10foundation · easy

    After applying a security update to a dependency, what should you do to confirm the Dependabot alert is resolved?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GitHub. “GH-500” is a trademark of its owner, used for identification only.