Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GitHub logo

GitHubAdvanced Security (GH-500)

Domain 3Objective 3

Secure Dependencies During Development GH-500 Practice Questions (Page 3)

Part of the Configure and use supply chain security (formerly Dependabot/Dependency Review) domain, which accounts for 15-20% of the GH-500 exam.

27questions here
6free pages
10concepts
15-20%of the exam

Questions 11–15

  1. 11application · medium

    A team uses Dependabot to update their Python dependencies. They have a group configured for 'runtime' dependencies and another for 'dev' dependencies. They notice that Dependabot is creating separate pull requests for each dependency in the 'dev' group instead of grouping them. What is the most likely cause?

    Select an answer first
  2. 12application · medium

    A company's legal team has approved a list of licenses that can be used in their projects. They want to ensure that no new dependency with a license outside this list is added. Which configuration should they use in Dependency Review?

    Select an answer first
  3. 13application · medium

    A team wants to enable Dependency Review on their repository. They have already enabled Dependabot alerts. What is the next step to enable Dependency Review?

    Select an answer first
  4. 14foundation · easy

    What does the 'lockfile-only' update strategy do in Dependabot?

    Select an answer first
  5. 15foundation · easy

    In the Dependency Review results, what does a 'vulnerability alert' indicate?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GitHub. “GH-500” is a trademark of its owner, used for identification only.