
GitHubAdvanced Security (GH-500)
Domain 3Objective 2
Detect, Prioritize, and Respond to Supply Chain Alerts GH-500 Practice Questions (Page 3)
Part of the Configure and use supply chain security (formerly Dependabot/Dependency Review) domain, which accounts for 15-20% of the GH-500 exam.
27questions here
6free pages
7concepts
15-20%of the exam
Questions 11–15
- 11
Which of the following is a key benefit of using security campaigns to remediate supply chain alerts?
Select an answer first - 12
What does the EPSS score primarily indicate about a vulnerability?
Select an answer first - 13
An organization receives a high volume of Dependabot alerts, many of which are for low-severity vulnerabilities with low EPSS scores. The security team wants to reduce alert fatigue while still being notified of serious risks. What should they configure?
Select an answer first - 14
A security team is creating a security campaign to remediate a vulnerability in a library that is used in both production and development dependencies. They want to prioritize production dependencies, but the campaign tool does not distinguish between them. What should they do?
Select an answer first - 15
A team is remediating a Dependabot alert for a vulnerability in a Python package. The patched version is available, but it requires a newer version of Python than the project currently uses. What should the team do?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GitHub. “GH-500” is a trademark of its owner, used for identification only.