
GitHubAdvanced Security (GH-500)
Domain 3Objective 1
Understand and Manage Dependency and Supply Chain Risks GH-500 Practice Questions (Page 2)
Part of the Configure and use supply chain security (formerly Dependabot/Dependency Review) domain, which accounts for 15-20% of the GH-500 exam.
14questions here
3free pages
5concepts
15-20%of the exam
Questions 6–10
- 6
A developer is reviewing the dependency graph for a Ruby on Rails application and sees that the 'nokogiri' gem is listed as a direct dependency. However, the developer knows they removed nokogiri from the Gemfile last week. Why does it still appear in the dependency graph?
Select an answer first - 7
Which of the following are valid SBOM export formats supported by GitHub?
Select an answer first - 8
A compliance officer asks for an SBOM of a .NET application to verify that no GPL-licensed libraries are used in production. The officer prefers a format that is human-readable and can be easily reviewed in a text editor. Which SBOM format should you export?
Select an answer first - 9
A company is adopting a 'shift-left' security approach and wants to identify supply chain risks as early as possible in the development lifecycle. They currently rely on Dependabot alerts, which only fire after a vulnerability is published. They want to proactively assess the risk of new dependencies before they are added to the codebase. What should they implement?
Select an answer first - 10
A security team wants to understand the full supply chain risk of a repository by identifying not only known vulnerabilities but also the licenses of all dependencies. They plan to use this information to enforce a policy that prohibits copyleft licenses. What should they use?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GitHub. “GH-500” is a trademark of its owner, used for identification only.