Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GitHub logo

GitHubAdvanced Security (GH-500)

Domain 6Objective 4

Manage CodeQL and Security Automation GH-500 Practice Questions (Page 2)

Part of the GitHub Security suites administration domain, which accounts for 10-15% of the GH-500 exam.

19questions here
4free pages
6concepts
10-15%of the exam

Questions 6–10

  1. 6application · medium

    A security team wants to enable CodeQL scanning on a new repository with minimal configuration. They need the default setup to run on every push and pull request, and they want to avoid writing a custom workflow from scratch. What should they do?

    Select an answer first
  2. 7application · medium

    A security admin needs to enable CodeQL scanning on over 200 repositories in an organization. They want to use a consistent configuration and avoid manual UI clicks. What is the most efficient approach?

    Select an answer first
  3. 8application · medium

    An organization has a policy that all CodeQL workflows must use a specific query pack and must not use the 'pull_request' trigger to avoid duplicate scans. They want to automate the enforcement of this policy across all repositories. What is the best way to implement this?

    Select an answer first
  4. 9foundation · easy

    What is the primary purpose of implementing approved custom CodeQL workflows across an organization?

    Select an answer first
  5. 10expert · hard

    An organization wants to audit CodeQL usage across all repositories. They need to know which repositories have CodeQL enabled, which use the default workflow, and which have custom workflows. They also want to identify repositories that have not run CodeQL in the last 30 days. What is the most efficient way to gather this information?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GitHub. “GH-500” is a trademark of its owner, used for identification only.