
GitHubAdvanced Security (GH-500)
Domain 5Objective 1
Understand Vulnerability Context and Remediation Frameworks GH-500 Practice Questions (Page 2)
Part of the Security operations: best practices, prioritization, and remediation domain, which accounts for 15-20% of the GH-500 exam.
27questions here
6free pages
8concepts
15-20%of the exam
Questions 6–10
- 6
A security team must prioritize two vulnerabilities. Vulnerability X is a critical CVE in a library used by an internal HR system that is only accessible via VPN. Vulnerability Y is a high CVE in a library used by a public marketing website that has no sensitive data. Both have known exploits. The team has resources to fix only one this week. Which should they fix first?
Select an answer first - 7
How can you verify that a remediation for a vulnerability is effective?
Select an answer first - 8
What does tracking the lifecycle of an alert involve?
Select an answer first - 9
After a developer applies a fix for a code scanning alert, the alert remains open in the GitHub Security tab. What is the most likely reason, and what should the developer do?
Select an answer first - 10
A Dependabot alert is raised for a vulnerability in a Python package. The package has a patched version, but updating it requires a major version bump that may break the application. What is the best course of action?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GitHub. “GH-500” is a trademark of its owner, used for identification only.