
GitHubAdvanced Security (GH-500)
Domain 2Objective 3
Manage and Respond to Secret Protection Alerts GH-500 Practice Questions (Page 4)
Part of the Configure and use Secret Protection (formerly secret scanning) domain, which accounts for 15-20% of the GH-500 exam.
25questions here
5free pages
6concepts
15-20%of the exam
Questions 16–20
- 16
A Secret Protection alert flags a string that matches a GitHub token pattern. The developer says it is a test token, but the security team cannot verify that it is not used in production. What is the safest action?
Select an answer first - 17
A Secret Protection alert identifies a Slack webhook URL in a public repository. The webhook is still active and posts to a company channel. What is the first step in the remediation process?
Select an answer first - 18
Which of the following is the most appropriate remediation action for a confirmed exposed API key?
Select an answer first - 19
A Secret Protection alert flags a string that looks like an Azure Storage account key, but the developer explains it is a sample value from Microsoft documentation. The team wants to prevent future alerts for this exact string. What should they do?
Select an answer first - 20
What should you do before deciding to resolve or dismiss a Secret Protection alert?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GitHub. “GH-500” is a trademark of its owner, used for identification only.