
GitHubAdvanced Security (GH-500)
Domain 6Objective 4
Manage CodeQL and Security Automation GH-500 Practice Questions (Page 1)
Part of the GitHub Security suites administration domain, which accounts for 10-15% of the GH-500 exam.
19questions here
4free pages
6concepts
10-15%of the exam
Questions 1–5
- 1
In a custom CodeQL workflow, which YAML key is used to specify the query suites or query files that CodeQL should run?
Select an answer first - 2
Which GitHub API is specifically designed to query and mutate data using a flexible, graph-based syntax, including security configuration settings?
Select an answer first - 3
A development team uses a monorepo with both JavaScript and Python code. They want CodeQL to analyze both languages, but the default workflow only detected JavaScript. They need to ensure Python is also analyzed. What should they do?
Select an answer first - 4
When enabling CodeQL at scale across many repositories, what is a key advantage of using the GitHub API over manually editing each repository?
Select an answer first - 5
An organization wants to enforce that all repositories use an approved CodeQL workflow that includes a specific query pack and a custom build step. They want to prevent developers from modifying the workflow. What is the most effective way to enforce this?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GitHub. “GH-500” is a trademark of its owner, used for identification only.