Where can you remove access to GitHub Advanced Security features for an individual repository in an organization? (Each answer presents part of the solution. Choose two.)
Which Dependabot configuration fields are required? (Each answer presents part of the solution. Choose three.)
In the pull request, how can developers avoid adding new dependencies with known vulnerabilities?
You need to run code scanning when files are modified in a specific directory. Which option can be used to complete line 3 in the workflow fragment below?
1. on:
2. push:
3.
Your security team requested that you enable the dependency graph. What happens when you enable this feature for your repository?
You are configuring code scanning with CodeQL. What is one impact of using a language matrix in your workflow?
Which of the following statements most accurately describes push protection for secret scanning custom patterns?​
Which of the following tasks can be performed by a security team as a proactive measure to help address secret scanning alerts? (Each answer presents a complete solution. Choose two.)
You have enabled security updates for a repository. When does GitHub mark a Dependabot alert as resolved for that repository?
A colleague ignores a code scanning alert. What are the implications of the colleague's action? (Each answer presents part of the solution. Choose three.)
Which of the following secret scanning features can verify whether a secret is still active?
Which of the following is the best way to prevent developers from adding secrets to the repository?
What filter or sort settings can be used to prioritize the secret scanning alerts that present the most risk?
Which organization policy lets organizations choose whether to allow members to view dependency insights?
If default code security settings have not been changed at the repository, organization, or enterprise level, which repositories receive Dependabot alerts?
A secret scanning alert should be closed as "used in tests" when a secret is:
Which syntax in a query suite tells CodeQL to look for one or more specified .ql files?
As a developer, you need to configure a code scanning workflow for a repository where GitHub Advanced Security is enabled. What minimum repository permission do you need?
Where can you find the vulnerable dependencies that GitHub detected in your repository?
As a contributor, you discovered a vulnerability in a repository. Where should you look for the instructions on how to report the vulnerability?
You are a maintainer of a repository and Dependabot notifies you of a vulnerability. Where could the vulnerability have been disclosed? (Each answer presents part of the solution. Choose two.)​
You are tasked with filtering queries in a CodeQL query suite. Which metadata tag matches on the last path component?
Which of the following features helps to prioritize secret scanning alerts that present an immediate risk?
Which of the following workflow events would trigger a dependency review? (Each answer presents a complete solution. Choose two.)​