
GitHubAdvanced Security (GH-500)
Domain 1Objective 4
Manage Access, Governance, and Supply Chain Security GH-500 Practice Questions (Page 2)
Part of the Describe GitHub Security suites, features, and ecosystem domain, which accounts for 15-20% of the GH-500 exam.
20questions here
4free pages
6concepts
15-20%of the exam
Questions 6–10
- 6
A company is required to provide a Software Bill of Materials (SBOM) for a critical application to a customer. The application is built from a monorepo with multiple packages. The company wants to generate the SBOM automatically as part of their CI/CD pipeline. What is the best approach?
Select an answer first - 7
What is a dependency in the context of software supply chain security?
Select an answer first - 8
A developer with write access to a repository reports that they can see a Dependabot alert for a critical vulnerability, but the 'Create security advisory' button is grayed out. The repository is owned by an organization. What is the most likely reason for this behavior?
Select an answer first - 9
A company is required to provide a list of all open-source dependencies and their licenses for a compliance audit. They use GitHub Enterprise Cloud. What is the most efficient way to generate this information?
Select an answer first - 10
A security manager needs to view and manage security alerts across all repositories in an organization, but they do not have admin access to each repository. What is the most appropriate way to grant them the necessary permissions?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GitHub. “GH-500” is a trademark of its owner, used for identification only.