
GitHubAdvanced Security (GH-500)
Domain 4Objective 1
Understand Code Scanning Approaches and Tooling GH-500 Practice Questions (Page 3)
Part of the Configure and use Code Security (formerly Code Scanning with CodeQL) domain, which accounts for 10-15% of the GH-500 exam.
24questions here
5free pages
5concepts
10-15%of the exam
Questions 11–15
- 11
A security team is choosing between CodeQL and a third-party tool for their JavaScript and TypeScript codebase. They need deep, customizable analysis and are willing to invest time in learning a query language. They also want to minimize the number of tools. What is the best choice?
Select an answer first - 12
What is the primary purpose of the SARIF format in the context of GitHub code scanning?
Select an answer first - 13
A team needs to write highly specific security rules that match their internal coding standards. Which tool characteristic should they prioritize when choosing between CodeQL and a third-party tool?
Select an answer first - 14
Which SARIF property is used by GitHub to uniquely identify a finding so that it can be tracked across multiple uploads?
Select an answer first - 15
What is the primary method for integrating a third-party static analysis tool like SonarQube with GitHub code scanning?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GitHub. “GH-500” is a trademark of its owner, used for identification only.