Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GitHub logo

GitHubAdvanced Security (GH-500)

Domain 5Objective 1

Understand Vulnerability Context and Remediation Frameworks GH-500 Practice Questions (Page 5)

Part of the Security operations: best practices, prioritization, and remediation domain, which accounts for 15-20% of the GH-500 exam.

27questions here
6free pages
8concepts
15-20%of the exam

Questions 21–25

  1. 21application · medium

    A code scanning alert flags a SQL injection vulnerability in a legacy PHP application. The CWE category is CWE-89. The team cannot upgrade the framework because it is end-of-life. What is the most appropriate remediation strategy?

    Select an answer first
  2. 22foundation · easy

    Which format correctly represents a CVE identifier?

    Select an answer first
  3. 23foundation · easy

    Why is asset criticality an important factor in prioritizing vulnerability remediation?

    Select an answer first
  4. 24foundation · easy

    What is the first step in the end-to-end remediation workflow after receiving a security alert?

    Select an answer first
  5. 25expert · hard

    A security engineer is handling a critical vulnerability in a production application. The advisory provides a patched version, but the patch requires a database schema migration that could cause downtime. The application is business-critical and cannot be taken offline during business hours. What is the best approach to remediate the vulnerability?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GitHub. “GH-500” is a trademark of its owner, used for identification only.