Pre-Winter Sale Discount Flat 70% Offer - Ends in 0d 00h 00m 00s - Coupon code: 70diswrap

Microsoft GH-500 Dumps

Page: 1 / 13
Total 125 questions

GitHub Advanced Security Exam Questions and Answers

Question 1

By default, which role can enable Dependabot alerts?

Options:

A.

Repository administrators

B.

Repository maintainers

C.

Security analysts

D.

Outside collaborators

Question 2

If default code security settings have not been changed at the repository, organization, or enterprise level, which repositories receive Dependabot alerts?

Options:

A.

Repositories owned by an enterprise account

B.

Private repositories

C.

None

D.

Repositories owned by an organization

Question 3

When using CodeQL, what extension stores query suite definitions?

Options:

A.

.yml

B.

.ql

C.

.qll

D.

.qls

Question 4

How many alerts are created when two instances of the same secret value are in the same repository?

Options:

A.

1

B.

2

C.

3

D.

4

Question 5

You need to run code scanning when files are modified in a specific directory. Which option can be used to complete line 3 in the workflow fragment below?

1. on:

2. push:

3.

Options:

A.

**foo

B.

(

C.

?

D.

paths:

Question 6

In a private repository, what minimum requirements does GitHub need to generate a dependency graph? (Each answer presents part of the solution. Choose two.)​

Options:

A.

Read-only access to all the repository's files

B.

Dependency graph enabled at the organization level for all new private repositories

C.

Write access to the dependency manifest and lock files for an enterprise

D.

Read-only access to the dependency manifest and lock files for a repository​

Question 7

Which of the following is the best way to prevent developers from adding secrets to the repository?

Options:

A.

Create a CODEOWNERS file

B.

Make the repository public

C.

Configure a security manager

D.

Enable push protection

Question 8

Which of the following formats are used to describe a code scanning alert from CodeQL?

Options:

A.

Common Weakness Enumeration (CWE)

B.

Vulnerability Exploitability eXchange (VEX)

C.

Common Vulnerabilities and Exposures (CVE)

D.

GitHub Security Advisory (GHSA)

Question 9

What is the minimum role needed in order to view the secret scanning alerts list within the Security tab of a repository?

Options:

A.

Admin

B.

Read

C.

Repository owner

D.

Write

Question 10

In the pull request, how can developers avoid adding new dependencies with known vulnerabilities?

Options:

A.

Enable Dependabot alerts.

B.

Add Dependabot rules.

C.

Add a workflow with the dependency review action.

D.

Enable Dependabot security updates.

Question 11

Which of the following statements most accurately describes push protection for secret scanning custom patterns?​

Options:

A.

Push protection must be enabled for all, or none, of a repository's custom patterns.

B.

Push protection is an opt-in experience for each custom pattern.

C.

Push protection is not available for custom patterns.

D.

Push protection is enabled by default for new custom patterns.​

Question 12

What is the first step you should take to fix an alert in secret scanning?

Options:

A.

Archive the repository.

B.

Update your dependencies.

C.

Revoke the alert if the secret is still valid.

D.

Remove the secret in a commit to the main branch.

Question 13

What is required to trigger code scanning on a specified branch?

Options:

A.

The repository must be private.

B.

Secret scanning must be enabled on the repository.

C.

Developers must actively maintain the repository.

D.

The workflow file must exist in that branch.

Question 14

What do you need to do before you can define a custom pattern for a repository?​

Options:

A.

Provide a regular expression for the format of your secret pattern.

B.

Add a secret scanning custom pattern.

C.

Enable secret scanning on the repository.

D.

Provide match requirements for the secret format.​

Stack Overflow

Question 15

What are Dependabot security updates?

Options:

A.

Automated pull requests that help you update dependencies that have known vulnerabilities

B.

Automated pull requests that keep your dependencies updated, even when they don’t have any vulnerabilities

C.

Automated pull requests to update the manifest to the latest version of the dependency

D.

Compatibility scores to let you know whether updating a dependency could cause breaking changes to your project

Question 16

Which GitHub Advanced Security options are available under the Security section of the GitHub Enterprise Server Management Console? (Each answer presents part of the solution. Choose two.)

Options:

A.

Secret scanning

B.

Code scanning

C.

Dependency review

D.

Dependabot version updates

Question 17

What is the first step in CodeQL analysis?

Options:

A.

Converting results produced during query execution

B.

Running CodeQL queries against the database

C.

Preparing the code by creating a CodeQL database

D.

Interpreting the query results

Question 18

By default, who will receive an email when a secret has been detected in a repository? (Each answer presents a complete solution. Choose two.)

Options:

A.

Security analyst

B.

User who committed the secret

C.

Users with the Admin repository role

D.

Users with the Write repository role

E.

Users with the Maintain repository role

Question 19

Assuming that no custom patterns are configured, what type of secret is detected by secret scanning?

Options:

A.

Usernames

B.

Personally Identifiable Information (PII)

C.

Private keys

D.

Sealed boxes

Question 20

Which of the following dependencies could trigger a Dependabot alert? (Each answer presents a complete solution. Choose two.)

Options:

A.

Indirect dependencies explicitly declared in a lockfile

B.

Loose dependencies declared in a manifest

C.

Direct dependencies explicitly declared in a manifest

D.

Direct dependencies at 08:00 UTC

Question 21

Which of the following secret scanning features can verify whether a secret is still active?

Options:

A.

Push protection

B.

Validity checks

C.

Branch protection

D.

Custom patterns

Question 22

Which Dependabot configuration fields are required? (Each answer presents part of the solution. Choose three.)

Options:

A.

directory

B.

package-ecosystem

C.

milestone

D.

schedule.interval

E.

allow

Question 23

Assuming there is no custom Dependabot behavior configured, where possible, what does Dependabot do after sending an alert about a vulnerable dependency in a repository?

Options:

A.

Creates a pull request to upgrade the vulnerable dependency to the minimum possible secure version

B.

Scans repositories for vulnerable dependencies on a schedule and adds those files to a manifest

C.

Constructs a graph of all the repository's dependencies and public dependents for the default branch

D.

Scans any push to all branches and generates an alert for each vulnerable repository

Question 24

A repository's dependency graph includes:

Options:

A.

Dependencies parsed from a repository's manifest and lock files.

B.

Annotated code scanning alerts from your repository's dependencies.

C.

A summary of the dependencies used in your organization's repositories.

D.

Dependencies from all your repositories.

Question 25

You are configuring code scanning with CodeQL. What is one impact of using a language matrix in your workflow?

Options:

A.

CodeQL excludes alerts for those dependencies specified in the language matrix.

B.

CodeQL is configured to run analysis sequentially.

C.

You can use the languages parameter under the init action.

D.

CodeQL will only analyze the languages in the matrix.

Question 26

You have enabled security updates for a repository. When does GitHub mark a Dependabot alert as resolved for that repository?

Options:

A.

When Dependabot creates a pull request to update dependencies

B.

When you dismiss the Dependabot alert

C.

When the pull request checks are successful

D.

When you merge a pull request that contains a security update

Question 27

Who can fix a code scanning alert on a private repository?​

Options:

A.

Users who have the Triage role within the repository

B.

Users who have Read permissions within the repository

C.

Users who have Write access to the repository

D.

Users who have the security manager role within the repository​

Question 28

Which of the following tasks can be performed by a security team as a proactive measure to help address secret scanning alerts? (Each answer presents a complete solution. Choose two.)

Options:

A.

Dismiss alerts that are older than 90 days.

B.

Configure a webhook to monitor for secret scanning alert events.

C.

Enable system for cross-domain identity management (SCIM) provisioning for the enterprise.

D.

Document alternatives to storing secrets in the source code.

Question 29

What role is required to change a repository's code scanning severity threshold that fails a pull request status check?

Options:

A.

Maintain

B.

Write

C.

Triage

D.

Admin

Question 30

As a contributor, you discovered a vulnerability in a repository. Where should you look for the instructions on how to report the vulnerability?

Options:

A.

support.md

B.

readme.md

C.

contributing.md

D.

security.md

Question 31

Assuming that notification and alert recipients are not customized, what does GitHub do when it identifies a vulnerable dependency in a repository where Dependabot alerts are enabled? (Each answer presents part of the solution. Choose two.)​

Options:

A.

It generates a Dependabot alert and displays it on the Security tab for the repository.

B.

It notifies the repository administrators about the new alert.

C.

It generates Dependabot alerts by default for all private repositories.

D.

It consults with a security service and conducts a thorough vulnerability review.​

Question 32

What is the best method to ensure all new code is scanned for vulnerabilities?

Options:

A.

Add the extended suite.

B.

Configure code owners.

C.

Set up a security policy.

D.

Configure code scanning.

Question 33

Dependabot has created a pull request. Which of the following commands should you use in a comment to prevent Dependabot from re-creating the same pull request?

Options:

A.

@dependabot recreate

B.

@dependabot ignore this dependency

C.

@dependabot close

D.

@dependabot rebase

Question 34

Using advanced setup, which code scanning configuration would help detect vulnerabilities before they are added to a shared branch?

Options:

A.

on:

issues:

B.

on:

pull_request:

C.

on:

schedule:

D.

on:

workflow_dispatch:

Question 35

What is the scope of the Enable all setting for Dependabot alerts at the organization level?

Options:

A.

Private repositories where GitHub Advanced Security is also enabled

B.

Related features for public repositories

C.

All repositories

D.

Only private repositories

Question 36

What kind of repository permissions do you need to request a Common Vulnerabilities and Exposures (CVE) identification number for a security advisory?​

Options:

A.

Maintain

B.

Admin

C.

Triage

D.

Write​

Question 37

When secret scanning detects a set of credentials on a public repository, what does GitHub do?

Options:

A.

It notifies the service provider who issued the secret.

B.

It displays a public alert in the Security tab of the repository.

C.

It scans the contents of the commits for additional secrets.

D.

It sends a notification to repository members.

Page: 1 / 13
Total 125 questions