
GitHubAdvanced Security (GH-500)
Domain 5Objective 5
Shift Left and Strengthen Preventive Security GH-500 Practice Questions (Page 1)
Part of the Security operations: best practices, prioritization, and remediation domain, which accounts for 15-20% of the GH-500 exam.
11questions here
3free pages
3concepts
15-20%of the exam
Questions 1–5
- 1
A team wants to enforce that all pull requests pass both code scanning and secret scanning checks before merging. They have enabled code scanning with CodeQL and push protection for secrets. However, they notice that secret scanning does not appear as a required check in the branch protection rules. What is the likely reason?
Select an answer first - 2
What is the primary purpose of enabling push protection for secret scanning in a GitHub repository?
Select an answer first - 3
A team uses GitHub Actions for CI/CD. They want to ensure that any pull request that introduces a new dependency with a known critical vulnerability is blocked from merging. Which approach should they use?
Select an answer first - 4
A repository has Dependabot alerts enabled, but the security team is overwhelmed by the number of alerts. They want to prioritize alerts that are actually exploitable in the context of their application. What should they do?
Select an answer first - 5
A repository uses a package.json file with many npm dependencies. The security team wants to automatically detect known vulnerabilities in these dependencies before they are merged into the main branch. Which approach should they use?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GitHub. “GH-500” is a trademark of its owner, used for identification only.