
GitHubAdvanced Security (GH-500)
Domain 3Objective 1
Understand and Manage Dependency and Supply Chain Risks GH-500 Practice Questions (Page 1)
Part of the Configure and use supply chain security (formerly Dependabot/Dependency Review) domain, which accounts for 15-20% of the GH-500 exam.
14questions here
3free pages
5concepts
15-20%of the exam
Questions 1–5
- 1
A company is required to provide an SBOM for a product that is distributed as a container image. The SBOM must include the dependencies of the application inside the container, as well as the base image components. What is the most effective way to generate this SBOM?
Select an answer first - 2
Which of the following information can you obtain from the dependency graph for a repository?
Select an answer first - 3
Which GitHub Advanced Security feature automatically monitors a repository's dependencies and alerts you when a known vulnerability is detected in a direct or transitive dependency?
Select an answer first - 4
A security auditor requires a machine-readable inventory of all direct and transitive dependencies in a Python repository, including license information, to review for compliance. The auditor specifically requests a format that is widely supported by their tooling. What should you do?
Select an answer first - 5
A security team is evaluating whether to use SPDX or CycloneDX for their SBOM exports. They need a format that supports the inclusion of vulnerability information directly in the SBOM, so they can share a single file that contains both the dependency list and known vulnerabilities. Which format should they choose?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GitHub. “GH-500” is a trademark of its owner, used for identification only.