Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GitHub logo

GitHubAdvanced Security (GH-500)

Domain 3Objective 3

Secure Dependencies During Development GH-500 Practice Questions (Page 2)

Part of the Configure and use supply chain security (formerly Dependabot/Dependency Review) domain, which accounts for 15-20% of the GH-500 exam.

27questions here
6free pages
10concepts
15-20%of the exam

Questions 6–10

  1. 6foundation · easy

    Which configuration option allows Dependency Review to ignore a specific dependency in a pull request?

    Select an answer first
  2. 7foundation · easy

    What does Dependency Review do when it detects a dependency with a license that is not allowed by the organization's policy?

    Select an answer first
  3. 8application · medium

    An organization has a strict policy that no GPL-licensed dependencies may be used in their commercial software. They use Dependency Review to enforce this policy. A developer creates a pull request that adds a new dependency with a GPL license. What will happen when the Dependency Review check runs?

    Select an answer first
  4. 9expert · hard

    A security engineer is reviewing a Dependency Review report on a pull request. The report shows a vulnerability in a transitive dependency that is not directly used by the project. The engineer wants to understand the impact and decide whether to block the merge. What should they do?

    Select an answer first
  5. 10application · medium

    A developer is about to merge a pull request that updates several dependencies. They want to ensure that the changes do not introduce any new vulnerable dependencies or license violations. What should they check before merging?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GitHub. “GH-500” is a trademark of its owner, used for identification only.