
GitHubAdvanced Security (GH-500)
Domain 5Objective 5
Shift Left and Strengthen Preventive Security GH-500 Practice Questions (Page 2)
Part of the Security operations: best practices, prioritization, and remediation domain, which accounts for 15-20% of the GH-500 exam.
11questions here
3free pages
3concepts
15-20%of the exam
Questions 6–10
- 6
When a developer attempts to push a commit containing a detected secret and push protection is enabled, what is the immediate outcome?
Select an answer first - 7
What is the main benefit of enabling code scanning to run on pull requests?
Select an answer first - 8
What does GitHub's dependency scanning primarily do for a repository?
Select an answer first - 9
A Dependabot alert indicates that a project dependency has a critical vulnerability. What is the recommended first action for a developer to take?
Select an answer first - 10
A team has enabled code scanning with CodeQL and push protection for secrets. However, they are seeing a high number of false positives from CodeQL, and developers are starting to ignore alerts. The security team wants to reduce alert fatigue while still catching real vulnerabilities. What should they do?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GitHub. “GH-500” is a trademark of its owner, used for identification only.