Pre-Winter Special Sale - 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: spcl70

Practice Free GH-500 GitHub Advanced Security Exam Exam Questions Answers With Explanation

We at Crack4sure are committed to giving students who are preparing for the Microsoft GH-500 Exam the most current and reliable questions . To help people study, we've made some of our GitHub Advanced Security Exam exam materials available for free to everyone. You can take the Free GH-500 Practice Test as many times as you want. The answers to the practice questions are given, and each answer is explained.

Question # 6

An organization owner can give view access to Dependabot alerts to which type of user?

A.

Members of a team with Read access to a different repository within the same organization

B.

Outside collaborators with Read access

C.

Members of a team with Write access to the repository

D.

Members of an enterprise unassigned to the repository

Question # 7

By default, what is the minimum role needed to bypass push protection in a repository?

A.

Maintain

B.

Write

C.

Admin

D.

Triage

Question # 8

You are configuring a CodeQL workflow for compiled languages. What happens if your workflow uses a language matrix?

A.

Analysis of other languages in your repository will fail unless you supply explicit build commands.

B.

Autobuild attempts to build the supported language that has the most source files in the repository.

C.

You may need to install additional software to use the autobuild process.

D.

Autobuild attempts to build each of the languages listed in the matrix.

Question # 9

What is a prerequisite to define a custom pattern for a repository?

A.

Change the repository visibility to Internal

B.

Close other secret scanning alerts

C.

Specify additional match criteria

D.

Enable secret scanning

Question # 10

When using CodeQL, what extension stores query suite definitions?

A.

.yml

B.

.ql

C.

.qll

D.

.qls

Question # 11

What does a CodeQL database of your repository contain??

A.

A build for Go projects to set up the project

B.

A build of the code and extracted data

C.

Build commands for C/C++, C#, and Java

D.

A representation of all of the source code?

GitHub

Agentic AI for AppSec Teams

Question # 12

As a developer with write access, you navigate to a code scanning alert in your repository. When will GitHub close this alert?

A.

After you triage the pull request containing the alert

B.

When you use data-flow analysis to find potential security issues in code

C.

After you find the code and click the alert within the pull request

D.

After you fix the code by committing within the pull request

Question # 13

Which security feature shows a vulnerable dependency in a pull request?

A.

Dependency graph

B.

Dependency review

C.

Dependabot alert

D.

The repository's Security tab

Question # 14

Where is secret scanning enabled on a private repository?

A.

In the code security settings

B.

Within a repository ruleset

C.

Within a secret.yml file in the repository

D.

In the code scanning default setup settings

Question # 15

Which features are part of GitHub Advanced Security in the context of GitHub Enterprise? (Each correct answer presents part of the solution. Choose two.)

A.

Dependency review

B.

Dependency graph

C.

Security policy

D.

Secret scanning

Question # 16

What is the format of the GitHub security advisory form?

A.

A CVE Numbering Authority (CNA) description format

B.

A Dependabot alert sent to the affected repositories

C.

A form matching the MITRE database security advisory format

D.

A form matching the Common Vulnerabilities and Exposures (CVE) description format

Question # 17

What is required to trigger code scanning on a specified branch?

A.

The repository must be private.

B.

Secret scanning must be enabled on the repository.

C.

Developers must actively maintain the repository.

D.

The workflow file must exist in that branch.

Question # 18

Why should you dismiss a code scanning alert?

A.

If you fix the code that triggered the alert

B.

To prevent developers from introducing new problems

C.

If it includes an error in code that is used only for testing

D.

If there is a production error in your code

Question # 19

Which of the following features helps to prioritize secret scanning alerts that present an immediate risk?

A.

Non-provider patterns

B.

Push protection

C.

Custom pattern dry runs

D.

Secret validation

Question # 20

When using code scanning and GitHub Actions on Windows, what is the relative difference between the minute consumption of code scanning jobs and jobs on Linux runners?

A.

2x higher

B.

5x higher

C.

10x higher

D.

No difference

Question # 21

You want to enforce an enterprise policy that allows repository administrators within all organizations to enable GitHub Advanced Security for their repositories. Which option should you choose for this policy?

A.

No policy

B.

Allow for all organizations

C.

Never allow

D.

Allow for selected organizations

Question # 22

What is the minimum role needed in order to view the secret scanning alerts list within the Security tab of a repository?

A.

Admin

B.

Read

C.

Repository owner

D.

Write

Question # 23

How many alerts are created when two instances of the same secret value are in the same repository?

A.

1

B.

2

C.

3

D.

4

Question # 24

Which CodeQL query suite provides queries of lower severity than the default query suite?

A.

github/codeql-go/ql/src@main

B.

github/codeql/cpp/ql/src@main

C.

security-extended

Question # 25

What is the first step you should take to fix an alert in secret scanning?

A.

Archive the repository.

B.

Update your dependencies.

C.

Revoke the alert if the secret is still valid.

D.

Remove the secret in a commit to the main branch.

Question # 26

What happens when you remove someone's access to a private repository?

A.

Local clones of the private repository are deleted.

B.

Team access to a private repository is revoked.

C.

Their forks of that private repository are deleted.

D.

Confidential information is deleted.

Question # 27

Which of the following dependencies could trigger a Dependabot alert? (Each answer presents a complete solution. Choose two.)

A.

Indirect dependencies explicitly declared in a lockfile

B.

Loose dependencies declared in a manifest

C.

Direct dependencies explicitly declared in a manifest

D.

Direct dependencies at 08:00 UTC

Question # 28

As a developer, you need to configure a code scanning workflow for a repository where GitHub Advanced Security is enabled. What minimum repository permission do you need?

A.

Write

B.

None

C.

Admin

D.

Read

Question # 29

Which of the following formats are used to describe a Dependabot alert? (Each answer presents a complete solution. Choose two.)?

A.

Common Weakness Enumeration (CWE)

B.

Exploit Prediction Scoring System (EPSS)

C.

Common Vulnerabilities and Exposures (CVE)

D.

Vulnerability Exploitability exchange (VEX)?

Question # 30

You need to run code scanning when files are modified in a specific directory. Which option can be used to complete line 3 in the workflow fragment below?

1. on:

2. push:

3.

A.

**foo

B.

(

C.

?

D.

paths:

Question # 31

After defining a secret scanning custom pattern, what is the final step before publishing the pattern?

A.

Defining a custom pattern

B.

Enabling push protection

C.

Adding additional match requirements

D.

Performing a dry run

Question # 32

Which of the following information can be found in a repository's Security tab?

A.

Number of alerts per GHAS feature

B.

Two-factor authentication (2FA) options

C.

Access management

D.

GHAS settings

Question # 33

Secret scanning will scan:?

A.

A continuous integration system.

B.

Any Git repository.

C.

The GitHub repository.

D.

External services.?

Question # 34

Which of the following workflow events would trigger a dependency review? (Each answer presents a complete solution. Choose two.)?

A.

pull_request

B.

workflow_dispatch

C.

trigger

D.

commit

Question # 35

Which of the following options are code scanning application programming interface (API) endpoints? (Each answer presents part of the solution. Choose two.)

A.

List all open code scanning alerts for the default branch

B.

Modify the severity of an open code scanning alert

C.

Get a single code scanning alert

D.

Delete all open code scanning alerts

Question # 36

Which GitHub Advanced Security options are available under the Security section of the GitHub Enterprise Server Management Console? (Each answer presents part of the solution. Choose two.)

A.

Secret scanning

B.

Code scanning

C.

Dependency review

D.

Dependabot version updates

Question # 37

Which top-level keys are mandatory for the dependabot.yml file? (Each answer presents part of the solution. Choose two.)

A.

updates

B.

version

C.

registries

D.

assignees

GH-500 PDF

$42

$139.99

3 Months Free Update

  • Printable Format
  • Value of Money
  • 100% Pass Assurance
  • Verified Answers
  • Researched by Industry Experts
  • Based on Real Exams Scenarios
  • 100% Real Questions

GH-500 PDF + Testing Engine

$57

$189.99

3 Months Free Update

  • Exam Name: GitHub Advanced Security Exam
  • Last Update: Oct 5, 2026
  • Questions and Answers: 125
  • Free Real Questions Demo
  • Recommended by Industry Experts
  • Best Economical Package
  • Immediate Access

GH-500 Engine

$48

$159.99

3 Months Free Update

  • Best Testing Engine
  • One Click installation
  • Recommended by Teachers
  • Easy to use
  • 3 Modes of Learning
  • State of Art Technology
  • 100% Real Questions included