Pre-Winter Sale Special - Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: mxmas70

Home > Microsoft > GitHub Administrator > GH-500

GH-500 GitHub Advanced Security Exam Question and Answers

Question # 4

Where can you remove access to GitHub Advanced Security features for an individual repository in an organization? (Each answer presents part of the solution. Choose two.)

A.

The enterprise's Settings tab

B.

The organization's Settings tab

C.

The repository's Settings tab

D.

The organization's Repository permissions

Full Access
Question # 5

Which Dependabot configuration fields are required? (Each answer presents part of the solution. Choose three.)

A.

directory

B.

package-ecosystem

C.

milestone

D.

schedule.interval

E.

allow

Full Access
Question # 6

In the pull request, how can developers avoid adding new dependencies with known vulnerabilities?

A.

Enable Dependabot alerts.

B.

Add Dependabot rules.

C.

Add a workflow with the dependency review action.

D.

Enable Dependabot security updates.

Full Access
Question # 7

You need to run code scanning when files are modified in a specific directory. Which option can be used to complete line 3 in the workflow fragment below?

1. on:

2. push:

3.

A.

**foo

B.

(

C.

?

D.

paths:

Full Access
Question # 8

Which patterns are secret scanning validity checks available to?

A.

High entropy strings

B.

Custom patterns

C.

Partner patterns

D.

Push protection patterns

Full Access
Question # 9

Your security team requested that you enable the dependency graph. What happens when you enable this feature for your repository?

A.

Admins of the repository will see dependency information in the dependency graph.

B.

Dependabot security updates create pull requests to upgrade those dependencies.

C.

New repositories will need to have dependency information enabled.

D.

GitHub generates Dependabot alerts for vulnerable dependencies.

Full Access
Question # 10

You are configuring code scanning with CodeQL. What is one impact of using a language matrix in your workflow?

A.

CodeQL excludes alerts for those dependencies specified in the language matrix.

B.

CodeQL is configured to run analysis sequentially.

C.

You can use the languages parameter under the init action.

D.

CodeQL will only analyze the languages in the matrix.

Full Access
Question # 11

What is the first step in CodeQL analysis?

A.

Converting results produced during query execution

B.

Running CodeQL queries against the database

C.

Preparing the code by creating a CodeQL database

D.

Interpreting the query results

Full Access
Question # 12

Which of the following statements most accurately describes push protection for secret scanning custom patterns?​

A.

Push protection must be enabled for all, or none, of a repository's custom patterns.

B.

Push protection is an opt-in experience for each custom pattern.

C.

Push protection is not available for custom patterns.

D.

Push protection is enabled by default for new custom patterns.​

Full Access
Question # 13

Why should you dismiss a code scanning alert?

A.

If you fix the code that triggered the alert

B.

To prevent developers from introducing new problems

C.

If it includes an error in code that is used only for testing

D.

If there is a production error in your code

Full Access
Question # 14

What happens when you remove someone's access to a private repository?

A.

Local clones of the private repository are deleted.

B.

Team access to a private repository is revoked.

C.

Their forks of that private repository are deleted.

D.

Confidential information is deleted.

Full Access
Question # 15

Which of the following tasks can be performed by a security team as a proactive measure to help address secret scanning alerts? (Each answer presents a complete solution. Choose two.)

A.

Dismiss alerts that are older than 90 days.

B.

Configure a webhook to monitor for secret scanning alert events.

C.

Enable system for cross-domain identity management (SCIM) provisioning for the enterprise.

D.

Document alternatives to storing secrets in the source code.

Full Access
Question # 16

You have enabled security updates for a repository. When does GitHub mark a Dependabot alert as resolved for that repository?

A.

When Dependabot creates a pull request to update dependencies

B.

When you dismiss the Dependabot alert

C.

When the pull request checks are successful

D.

When you merge a pull request that contains a security update

Full Access
Question # 17

A colleague ignores a code scanning alert. What are the implications of the colleague's action? (Each answer presents part of the solution. Choose three.)

A.

A dangerous argument could be passed to functions.

B.

Data could be used insecurely.

C.

GitHub removes the alert after sixty days.

D.

Webhooks and the code scanning API remove the alert.

E.

Sensitive information could be leaked.

Full Access
Question # 18

Which of the following secret scanning features can verify whether a secret is still active?

A.

Push protection

B.

Validity checks

C.

Branch protection

D.

Custom patterns

Full Access
Question # 19

Which of the following would raise secret scanning alerts?

A.

GitHub personal access token

B.

Structured Query Language (SQL) injection

C.

Cross-site scripting (XSS)

D.

Server-side request forgery

Full Access
Question # 20

What are Dependabot security updates?

A.

Automated pull requests that help you update dependencies that have known vulnerabilities

B.

Automated pull requests that keep your dependencies updated, even when they don’t have any vulnerabilities

C.

Automated pull requests to update the manifest to the latest version of the dependency

D.

Compatibility scores to let you know whether updating a dependency could cause breaking changes to your project

Full Access
Question # 21

Which of the following is the best way to prevent developers from adding secrets to the repository?

A.

Create a CODEOWNERS file

B.

Make the repository public

C.

Configure a security manager

D.

Enable push protection

Full Access
Question # 22

Where can you find a deleted line of code that contained a secret value?

A.

Insights

B.

Issues

C.

Commits

D.

Dependency graph

Full Access
Question # 23

What filter or sort settings can be used to prioritize the secret scanning alerts that present the most risk?

A.

Sort to display the oldest first

B.

Sort to display the newest first

C.

Filter to display active secrets

D.

Select only the custom patterns

Full Access
Question # 24

What is required to trigger code scanning on a specified branch?

A.

The repository must be private.

B.

Secret scanning must be enabled on the repository.

C.

Developers must actively maintain the repository.

D.

The workflow file must exist in that branch.

Full Access
Question # 25

The autobuild step in the CodeQL workflow has failed. What should you do?

A.

Remove specific build steps.

B.

Compile the source code.

C.

Remove the autobuild step from your code scanning workflow and add specific build steps.

D.

Use CodeQL, which implicitly detects the supported languages in your code base.

Full Access
Question # 26

Which organization policy lets organizations choose whether to allow members to view dependency insights?

A.

Enable all

B.

Enabled

C.

Disabled

D.

No policy

Full Access
Question # 27

If default code security settings have not been changed at the repository, organization, or enterprise level, which repositories receive Dependabot alerts?

A.

Repositories owned by an enterprise account

B.

Private repositories

C.

None

D.

Repositories owned by an organization

Full Access
Question # 28

A secret scanning alert should be closed as "used in tests" when a secret is:

A.

In the readme.md file.

B.

In a test file.

C.

Solely used for tests.

D.

Not a secret in the production environment.

Full Access
Question # 29

Which syntax in a query suite tells CodeQL to look for one or more specified .ql files?

A.

query

B.

qlpack

C.

qls

Full Access
Question # 30

As a developer, you need to configure a code scanning workflow for a repository where GitHub Advanced Security is enabled. What minimum repository permission do you need?

A.

Write

B.

None

C.

Admin

D.

Read

Full Access
Question # 31

Where can you find the vulnerable dependencies that GitHub detected in your repository?

A.

In Dependabot alerts

B.

In secret scanning alerts

C.

In security advisories

D.

In code scanning alerts

Full Access
Question # 32

As a contributor, you discovered a vulnerability in a repository. Where should you look for the instructions on how to report the vulnerability?

A.

support.md

B.

readme.md

C.

contributing.md

D.

security.md

Full Access
Question # 33

Where can you view code scanning results from CodeQL analysis?

A.

The repository's code scanning alerts

B.

A CodeQL database

C.

A CodeQL query pack

D.

At Security advisories

Full Access
Question # 34

You are a maintainer of a repository and Dependabot notifies you of a vulnerability. Where could the vulnerability have been disclosed? (Each answer presents part of the solution. Choose two.)​

A.

In the National Vulnerability Database

B.

In the dependency graph

C.

In security advisories reported on GitHub

D.

In manifest and lock files

Full Access
Question # 35

You are tasked with filtering queries in a CodeQL query suite. Which metadata tag matches on the last path component?

A.

query path

B.

tags contain all

C.

query filename

D.

tags contain

Full Access
Question # 36

Which of the following features helps to prioritize secret scanning alerts that present an immediate risk?

A.

Non-provider patterns

B.

Push protection

C.

Custom pattern dry runs

D.

Secret validation

Full Access
Question # 37

Which of the following workflow events would trigger a dependency review? (Each answer presents a complete solution. Choose two.)​

A.

pull_request

B.

workflow_dispatch

C.

trigger

D.

commit

Full Access