
GitHubAdvanced Security (GH-500)
Domain 3Objective 2
Detect, Prioritize, and Respond to Supply Chain Alerts GH-500 Practice Questions (Page 4)
Part of the Configure and use supply chain security (formerly Dependabot/Dependency Review) domain, which accounts for 15-20% of the GH-500 exam.
27questions here
6free pages
7concepts
15-20%of the exam
Questions 16–20
- 16
A security team wants to reduce alert fatigue by auto-dismissing alerts for vulnerabilities with low EPSS scores. However, they are concerned that some critical dependencies may have low EPSS scores but still be high-risk due to their usage. What should they do?
Select an answer first - 17
When prioritizing supply chain alerts, how should EPSS scores be used?
Select an answer first - 18
What is the most direct way to resolve a Dependabot alert for a vulnerable dependency?
Select an answer first - 19
Which of the following criteria can be used in an auto-dismiss rule for supply chain alerts?
Select an answer first - 20
What is a common workflow element you can define when configuring a security campaign?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GitHub. “GH-500” is a trademark of its owner, used for identification only.