GitHub Advanced Security Exam Questions and Answers
By default, which role can enable Dependabot alerts?
If default code security settings have not been changed at the repository, organization, or enterprise level, which repositories receive Dependabot alerts?
When using CodeQL, what extension stores query suite definitions?
How many alerts are created when two instances of the same secret value are in the same repository?
You need to run code scanning when files are modified in a specific directory. Which option can be used to complete line 3 in the workflow fragment below?
1. on:
2. push:
3.
In a private repository, what minimum requirements does GitHub need to generate a dependency graph? (Each answer presents part of the solution. Choose two.)
Which of the following is the best way to prevent developers from adding secrets to the repository?
Which of the following formats are used to describe a code scanning alert from CodeQL?
What is the minimum role needed in order to view the secret scanning alerts list within the Security tab of a repository?
In the pull request, how can developers avoid adding new dependencies with known vulnerabilities?
Which of the following statements most accurately describes push protection for secret scanning custom patterns?
What is the first step you should take to fix an alert in secret scanning?
What is required to trigger code scanning on a specified branch?
What do you need to do before you can define a custom pattern for a repository?
What are Dependabot security updates?
Which GitHub Advanced Security options are available under the Security section of the GitHub Enterprise Server Management Console? (Each answer presents part of the solution. Choose two.)
What is the first step in CodeQL analysis?
By default, who will receive an email when a secret has been detected in a repository? (Each answer presents a complete solution. Choose two.)
Assuming that no custom patterns are configured, what type of secret is detected by secret scanning?
Which of the following dependencies could trigger a Dependabot alert? (Each answer presents a complete solution. Choose two.)
Which of the following secret scanning features can verify whether a secret is still active?
Which Dependabot configuration fields are required? (Each answer presents part of the solution. Choose three.)
Assuming there is no custom Dependabot behavior configured, where possible, what does Dependabot do after sending an alert about a vulnerable dependency in a repository?
A repository's dependency graph includes:
You are configuring code scanning with CodeQL. What is one impact of using a language matrix in your workflow?
You have enabled security updates for a repository. When does GitHub mark a Dependabot alert as resolved for that repository?
Who can fix a code scanning alert on a private repository?
Which of the following tasks can be performed by a security team as a proactive measure to help address secret scanning alerts? (Each answer presents a complete solution. Choose two.)
What role is required to change a repository's code scanning severity threshold that fails a pull request status check?
As a contributor, you discovered a vulnerability in a repository. Where should you look for the instructions on how to report the vulnerability?
Assuming that notification and alert recipients are not customized, what does GitHub do when it identifies a vulnerable dependency in a repository where Dependabot alerts are enabled? (Each answer presents part of the solution. Choose two.)
What is the best method to ensure all new code is scanned for vulnerabilities?
Dependabot has created a pull request. Which of the following commands should you use in a comment to prevent Dependabot from re-creating the same pull request?
Using advanced setup, which code scanning configuration would help detect vulnerabilities before they are added to a shared branch?
What is the scope of the Enable all setting for Dependabot alerts at the organization level?
What kind of repository permissions do you need to request a Common Vulnerabilities and Exposures (CVE) identification number for a security advisory?
When secret scanning detects a set of credentials on a public repository, what does GitHub do?