Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GitHub logo

GitHubAdvanced Security (GH-500)

Domain 4Objective 2

Set up and Configure Code Security GH-500 Practice Questions (Page 4)

Part of the Configure and use Code Security (formerly Code Scanning with CodeQL) domain, which accounts for 10-15% of the GH-500 exam.

24questions here
5free pages
6concepts
10-15%of the exam

Questions 16–20

  1. 16application · medium

    A team has a repository with both Python and JavaScript code. They want to run code scanning on both languages using a single workflow. What is the best way to configure the workflow?

    Select an answer first
  2. 17application · medium

    A team has a JavaScript project that needs to be scanned with two different Node.js versions (14 and 16). They want to use a matrix strategy. What should they include in the matrix?

    Select an answer first
  3. 18application · medium

    A team wants to run code scanning on both Ubuntu and Windows to catch platform-specific issues. They are using a matrix strategy. What should they include in the matrix?

    Select an answer first
  4. 19application · medium

    A development team uses GitHub Actions for CI/CD. They want to enable code scanning for a Java repository that uses Maven. The team wants to run the scan on every push and also on a weekly schedule. Which workflow configuration should they use?

    Select an answer first
  5. 20application · medium

    A company uses a third-party SAST tool that generates SARIF output. They want to see these results in GitHub code scanning. What is the recommended way to integrate this?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GitHub. “GH-500” is a trademark of its owner, used for identification only.