GH-500 Verified 2026 Edition

GitHub Advanced SecurityPractice Test

Master the GitHub Advanced Security with the official PlanetCert Practice Test. Access real exam questions, professional-grade detailed explanations, and our advanced adaptive simulator. Pass your certification exam on the first attempt.

232 Total Questions
1 Included Version Get all versions for the price of one
English Edition
All-In-One Bundle
$79.99
$75.99
  • Interactive Simulator & AI
  • Detailed Explanations
  • Study, Timed & Flashcard Mode
  • Lifetime Access & Updates

Instant lifetime access • Secure checkout

Why Study with PlanetCert?

The Latest Questions

Practice questions and exam topics aligned with the current exam objectives.

Detailed Explanations

Go beyond the answer. Master the material with comprehensive learning and professional explanations for every concept.

AI

AI-Powered Insights

Personalized preparation guidance that adapts to your performance and identifies weak spots automatically.

Exam Information

Official specifications published by Microsoft

Exam Format

100 min
50-60
700
Intermediate

Registration

$99 USD
Pearson VUE or online proctoring
English, Spanish, Portuguese (Brazil), Korean +1 more

Validity

2 years
Pass exam again after 2 years; Complete renewal assessment (if available)

GH-500 Exam Topics and Domains

GH-500 is organized into 5 weighted domains. Expect to work with GitHub Secret Scanning, GitHub Actions, CodeQL, GitHub Code Scanning, and more.

1

Describe the GHAS security features and functionality

15%

Contrast GHAS features and their role in the security ecosystem

Security features for open source vs GHAS with GHEC/GHESSecurity Overview features and benefitsSecret scanning vs code scanning differencesIntegrated security in SDLC
  • Differentiate the security features that come automatically for open source projects, and what features are available when GHAS is paired with GHEC or GHES
  • Describe the features and benefits of Security Overview
  • Describe the differences between secret scanning and code scanning
  • Describe how secret scanning, code scanning, and Dependabot create a more secure software development life cycle
  • Contrast a security scenario with isolated security review and an advanced scenario, with security integrated into each step of the software development life cycle

Explain and use specific GHAS features

Vulnerable dependency identificationActing on GHAS alertsAccess management for security featuresDependabot alerts in SDLC
  • Describe how vulnerable dependencies are identified (by looking at the manifest files and comparing with databases of known vulnerabilities)
  • Choose how to act on alerts from GHAS
  • Explain the implications of ignoring an alert
  • Explain the role of a developer when they discover a security alert
  • Describe the differences in access management to view alerts for different security features
  • Identify where to use Dependabot alerts in the software development lifecycle
2

Configure and use secret scanning

15%

Configure and use Secret Scanning

Secret scanning fundamentalsPush protectionValidity checksSecret scanning availability and configurationResponding to secret scanning alerts
  • Describe secret scanning
  • Describe push protection
  • Describe validity checks
  • Contrast secret scanning availability for public and private repositories
  • Enable secret scanning for private repositories
  • Pick an appropriate response to a secret scanning alert
  • Determine if an alert is generated for a given secret, pattern, or service provider
  • Determine if a given user role will see secret scanning alerts and how they will be notified

Customize default secret scanning behavior

Alert recipient configurationFile exclusionsCustom secret scanning
  • Configure the recipients of a secret scanning alert (also includes how to provide access to members and teams other than admins)
  • Exclude certain files from being scanned for secrets
  • Enable custom secret scanning for a repository
3

Configure and use Dependabot and Dependency Review

35%

Describe tools for managing vulnerabilities in dependencies

Dependency graph fundamentalsSoftware Bill of Materials (SBOM)Dependency vulnerabilitiesDependabot featuresDependency Review
  • Define the dependency graph
  • Describe how the dependency graph is generated
  • Describe what a Software Bill of Materials (SBOM) is, and the SBOM format used by GitHub
  • Define a dependency vulnerability
  • Describe Dependabot alerts
  • Describe Dependabot security updates
  • Describe Dependency Review
  • Describe how alerts are generated for vulnerable dependencies (driven from the dependency graph, sourced from the GitHub Advisory Database)
  • Describe the difference between Dependabot and Dependency Review

Enable and configure tools for managing vulnerable dependencies

Dependabot alerts configurationDependabot configuration fileDependabot RulesDependency Review workflowsNotification configuration
  • Identify the default settings for Dependabot alerts in public and private repositories
  • Identify the permissions and roles required to enable Dependabot alerts
  • Identify the permissions and roles required to view Dependabot alerts
  • Enable Dependabot alerts for private repositories
  • Enable Dependabot alerts for organizations
  • Create a valid Dependabot configuration file to group security updates
  • Create a Dependabot Rule to auto-dismiss low severity alerts until a patch is available
  • Create a Dependency Review GitHub Actions workflow
  • Configure license checks and custom severity thresholds in a Dependency Review workflow
  • Configure notifications for vulnerable dependencies

Identify and remediate vulnerable dependencies

Identifying vulnerabilitiesEnabling automated security updatesRemediating vulnerabilities
  • Identify a vulnerable dependency from a Dependabot alert
  • Identify vulnerable dependencies from a pull request
  • Enable Dependabot security updates
  • Remedy a vulnerability from a Dependabot alert in the Security tab (could include updating or removing the dependency)
  • Remedy a vulnerability from a Dependabot alert in the context of a pull request (could include updating or removing the dependency)
  • Take action on any Dependabot alerts by testing and merging pull requests
4

Configure and use Code Scanning with CodeQL

25%

Use code scanning with third-party tools

Third-party code scanning setupCodeQL vs third-party CI integrationSARIF upload
  • Enable code scanning for use with a third-party analysis
  • Contrast the steps for using CodeQL versus third party analysis when enabling code scanning
  • Contrast how to implement CodeQL analysis in a GitHub Actions workflow versus a third-party CI tool
  • Upload 3rd party SARIF results via the SARIF endpoint

Describe and enable code scanning

Code scanning in SDLCCode scanning workflow frequencyWorkflow triggers and customizationViewing and interpreting resultsTroubleshooting and customizationAlert management
  • Describe how code scanning fits in the software development life cycle
  • Contrast the frequency of code scanning workflows (scheduled versus triggered by events)
  • Choose a triggering event for a given development pattern (for example, in a pull request and for specific files)
  • Edit the default template for Actions workflow to fit an active, open source, production repository
  • Describe how to view code scanning results from CodeQL analysis
  • Troubleshoot a failing code scanning workflow using CodeQL, including creating or changing a custom configuration in the CodeQL workflow
  • Follow the data flow through code using the show paths experience
  • Explain the reason for a code scanning alert given documentation linked from the alert
  • Determine if and why a code scanning alert needs to be dismissed
  • Describe potential shortfalls in CodeQL via model of compilation and language support
  • Explain the purpose of defining a SARIF category
5

Describe GitHub Advanced Security best practices, results, and how to take corrective measures

10%

GitHub Advanced Security results & best practices

CVE and CWE in security alertsAlert management decision-makingCodeQL query suites and analysisTeam roles and responsibilitiesCode scanning configuration best practicesSecret scanning remediation prioritizationRepository Rulesets for security enforcementEarly vulnerability identification
  • Use a Common Vulnerabilities and Exposures (CVE) and Common Weakness Enumeration (CWE) to describe a GitHub Advanced Security alert and list potential remediation
  • Describe the decision-making process for closing and dismissing security alerts (documenting the dismissal, making a decision based on data)
  • Describe the default CodeQL query suites
  • Describe how CodeQL analyzes code and produces results, including differences between compiled and interpreted language
  • Determine the roles and responsibilities of development and security teams on a software development workflow
  • Describe how the severity threshold for code scanning pull request status checks can be changed
  • Explain how filters and sorting can be used to prioritize secret scanning remediation (validity:active)
  • Explain how CodeQL & Dependency Review workflows can be enforced with Repository Rulesets
  • Describe how code scanning can be configured to identify and remediate vulnerabilities earlier (scanning upon pull request)
  • Describe how secret scanning can be configured to identify and remediate vulnerabilities earlier (enabling push protection)
  • Describe how dependency analysis can be configured to identify and remediate vulnerabilities earlier (enable dependency review to scan upon pull request)

How do I earn this certification?

Passing GH-500 earns the GitHub Advanced Security certification. It sits in the GitHub Security track.

Next Level Options
  • Future GitHub Expert-level certifications Advanced GitHub certifications (as they become available)
  • Microsoft Security certifications Complementary Microsoft security certifications
Alternative Paths

Practice with Precision

The PlanetCert Simulator mirrors the real exam environment with authentic questions and timed pressure.

Launch Simulator

How to study for this exam?

The most effective way to prepare for GH-500 is by using the PlanetCert Simulator to practice questions and review detailed explanations.

What's changed on this exam?

Current Status
  • ACTIVE
  • Last content update: 2025-05-20
  • Announcement date: 2024-06-01
Updates
  • CodeQL Latest Continuous updates to query suites and language support • Release date: 2025-ongoing
  • Dependabot 3.0 Enhanced grouping and auto-dismiss rules now in exam scope • Release date: 2024-12-01
  • Repository Rulesets GA Policy enforcement now testable topic in Domain 5 • Release date: 2024-09-01

Who should take this exam?

  • Intermediate-level experience in GitHub Enterprise Administration
  • Deep understanding of GitHub and its security features
  • Hands-on experience in securing software development workflows
  • Experience as system administrator, software developer, or application administrator

Your Complete Exam Solution

Best-In-Class Practice Tests

Authentic, regularly updated questions that mirror the real exam. Verified, current material — not recycled dumps.

Topical Breakdown

Study by domain, pinpoint weak areas, and focus your time where it matters most. Every topic mapped to the official syllabus.

Flashcard Mode

Rapid-fire review to reinforce key concepts. Flip through questions and answers at your own pace before exam day.

See How You Compare Against Yourself

✕
✕
✕

Other Exam Prep

  • Outdated question dumpsRecycled, often inaccurate material
  • No explanationsMemorize answers without understanding
  • Static PDF filesNo interactive practice or feedback
  • Subscription feesRecurring charges, access expires
✓
✓
✓

PlanetCert

  • Verified, current questionsUpdated weekly to match live exam objectives
  • Expert-written rationalesUnderstand every concept, not just the answer
  • Session tracking & exam progressTrack every attempt, see your growth over time
  • Lifetime access, one pricePay once — updates included forever
CERTIFIEDGH-500

Study Naturally, Study Responsibly

Join thousands of certified professionals who trusted PlanetCert to pass on the first attempt.

Try Free Demo
Secure Checkout Lifetime Access Money-back Guarantee