
GitHubAdvanced Security (GH-500)
Domain 4Objective 1
Understand Code Scanning Approaches and Tooling GH-500 Practice Questions (Page 1)
Part of the Configure and use Code Security (formerly Code Scanning with CodeQL) domain, which accounts for 10-15% of the GH-500 exam.
24questions here
5free pages
5concepts
10-15%of the exam
Questions 1–5
- 1
A team runs two different code scanning tools in their CI pipeline. Both tools generate SARIF files for the same commit. They want to see all results in the GitHub Security tab. What is the correct approach?
Select an answer first - 2
When deciding between CodeQL and a third-party tool like Semgrep for a new project, which factor is most directly related to the programming languages used in the repository?
Select an answer first - 3
A company wants to enable code scanning on a repository that contains only C# code. They want to use GitHub's native solution. What is the most straightforward way to achieve this?
Select an answer first - 4
A developer is uploading a SARIF file to GitHub code scanning. The file contains results for a file that is in a different repository. What will happen?
Select an answer first - 5
A team uploads a SARIF file that contains multiple alerts for the same vulnerability in the same location. They notice that the Security tab shows only one alert. What is the reason for this?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GitHub. “GH-500” is a trademark of its owner, used for identification only.