Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GitHub logo

GitHubAdvanced Security (GH-500)

Domain 3Objective 1

Understand and Manage Dependency and Supply Chain Risks GH-500 Practice Questions (Page 3)

Part of the Configure and use supply chain security (formerly Dependabot/Dependency Review) domain, which accounts for 15-20% of the GH-500 exam.

14questions here
3free pages
5concepts
15-20%of the exam

Questions 11–14

  1. 11foundation · easy

    What is a key difference between the SPDX and CycloneDX SBOM formats?

    Select an answer first
  2. 12application · medium

    A team has just enabled the dependency graph for a large monorepo that contains multiple package manifests (package.json, requirements.txt, Gemfile). After 24 hours, the dependency graph shows no data. What is the most likely reason for this?

    Select an answer first
  3. 13foundation · easy

    What is the primary purpose of a Software Bill of Materials (SBOM) in the context of supply chain security?

    Select an answer first
  4. 14application · medium

    A developer notices that the dependency graph for a Go repository shows a vulnerability in a package that is not directly imported in any source file. The developer is confused because they don't see it in their go.mod. What should you explain?

    Select an answer first
Finished these 4 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to GH-500

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GitHub. “GH-500” is a trademark of its owner, used for identification only.