Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GitHub logo

GitHubAdvanced Security (GH-500)

Domain 5Objective 1

Understand Vulnerability Context and Remediation Frameworks GH-500 Practice Questions (Page 3)

Part of the Security operations: best practices, prioritization, and remediation domain, which accounts for 15-20% of the GH-500 exam.

27questions here
6free pages
8concepts
15-20%of the exam

Questions 11–15

  1. 11foundation · easy

    How does a GitHub Security Advisory relate to a Dependabot alert?

    Select an answer first
  2. 12expert · hard

    A security team has remediated a Dependabot alert by updating a dependency. The alert closed automatically. Later, a new Dependabot alert appears for the same CVE in a different repository. What should the team do?

    Select an answer first
  3. 13application · medium

    A security team has two Dependabot alerts to triage. Alert A is for a critical CVE in a library used by an internal tool that only a few employees access. Alert B is for a moderate CVE in a library used by a public-facing API that processes customer data. Both have known exploits. Which alert should be prioritized?

    Select an answer first
  4. 14foundation · easy

    How is the severity of a vulnerability typically represented in a GitHub Security Advisory?

    Select an answer first
  5. 15application · medium

    A developer receives a GitHub Security Advisory for a vulnerability in a production dependency. The advisory lists affected versions and a patched version. The developer updates the dependency and the Dependabot alert disappears. What should the developer do next to complete the remediation workflow?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GitHub. “GH-500” is a trademark of its owner, used for identification only.