
GitHubAdvanced Security (GH-500)
Domain 5Objective 1
Understand Vulnerability Context and Remediation Frameworks GH-500 Practice Questions (Page 1)
Part of the Security operations: best practices, prioritization, and remediation domain, which accounts for 15-20% of the GH-500 exam.
27questions here
6free pages
8concepts
15-20%of the exam
Questions 1–5
- 1
A security engineer receives a Dependabot alert for a vulnerability in a JavaScript library used by a customer-facing web application. The CVE has a CVSS score of 9.8, but the vulnerable function is only called in an administrative endpoint that requires authentication. The application is behind a Web Application Firewall (WAF) that blocks most external traffic. The team has limited remediation resources this sprint. What should the engineer prioritize?
Select an answer first - 2
Which of the following is a common remediation action for a vulnerable dependency?
Select an answer first - 3
A security team is triaging a new GitHub Security Advisory. The advisory has a CVSS score of 7.5, but the affected component is not used in any of the organization's repositories. What should the team do?
Select an answer first - 4
A Dependabot alert is raised for a vulnerability in a library that is only used in a development tool, not in production. The vulnerability has a CVSS score of 9.0, but the tool is only used by developers on their local machines. The team is considering dismissing the alert. What should they do?
Select an answer first - 5
What is the primary purpose of a CVE identifier?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GitHub. “GH-500” is a trademark of its owner, used for identification only.