GitHub Advanced Security Free Sample Questions

Create a free account to browse all 20 sample questions. The full practice test includes 232 questions. Use the simulator for timed and flashcard mode.

Try Simulator

GH-500 Sample Questions

  1. Question 1

    Q1

    A financial services company is implementing GitHub Advanced Security for their new Go-based microservices application. The security team requires that any new dependency added to a pull request must be checked against a list of pre-approved licenses. If a non-approved license is detected, the pull request must be blocked from merging. Which GitHub feature and configuration should be used to enforce this policy?

    Show answer & explanation

    Correct answer: B

    The Dependency Review feature, implemented as a GitHub Actions workflow (dependency-review-action), is specifically designed for this purpose. It runs on pull requests and can be configured with allow-licenses or deny-licenses to check for license compliance. By making this workflow a required status check, it can effectively block pull requests that introduce dependencies with non-compliant licenses. The dependabot.yml file is for configuring Dependabot updates, not for license checks on pull requests. Repository rulesets can enforce that the workflow runs, but the license logic is within the action itself. Secret scanning does not handle dependency licenses.

  2. Question 2

    Q2Multiple answers

    A DevOps team manages a large monorepo containing multiple microservices, each in its own directory with a different package ecosystem (e.g., /app-a uses npm, /app-b uses Maven, /app-c uses pip). The team wants to enable Dependabot security updates but is concerned about being overwhelmed by pull requests. They want to group all npm updates and all Maven updates into separate, single weekly pull requests. How should the dependabot.yml file be configured to achieve this? (Select TWO)

    Show answer & explanation

    Correct answers: B, C

    For a monorepo with multiple ecosystems, you must define a separate block for each package-ecosystem and specify its directory. This tells Dependabot where to find the manifest files for each service.

    The groups key is the correct mechanism for bundling multiple dependency updates into a single pull request, reducing PR noise. You would define a group for npm and another for Maven within their respective ecosystem blocks.

  3. Question 3

    Q3

    A security engineer is troubleshooting a CodeQL workflow for a compiled language (Java) that runs successfully on pushes to the main branch but fails consistently on pull requests from feature branches. The error occurs during the Initialize CodeQL step. The workflow is triggered by on: [push, pull_request]. What is the most probable reason for this discrepancy?

    Show answer & explanation

    Correct answer: B

    Workflows triggered by pull_request from forks run in a restricted context with a read-only token and no access to secrets. This can cause the Initialize CodeQL step to fail if it needs to access certain resources or if the analysis is complex. To analyze code from forks securely, the workflow should be changed to use the pull_request_target event, which runs in the context of the base repository but checks out the code from the pull request's HEAD commit. This is a common and critical distinction for securing workflows that run on code from external contributors.

  4. Question 4

    Q4

    True or False: When secret scanning push protection is enabled for a repository, a user with admin permissions can push a commit containing a detected secret without bypassing the protection.

    Show answer & explanation

    Correct answer: B

    Push protection applies to all users, regardless of their permissions. A user, including an administrator, must explicitly bypass the block by providing a reason. The protection is not automatically disabled for administrators; they are subject to the same initial block as any other contributor.

  5. Question 5

    Q5

    An organization wants to enforce a policy where all pull requests targeting the main branch must have a successful CodeQL analysis and a successful Dependency Review check before they can be merged. No administrator should be able to override this requirement. What is the most effective way to implement this strict enforcement?

    Show answer & explanation

    Correct answer: B

    While branch protection rules can require status checks, administrators can typically override them. Repository rulesets provide a more powerful and flexible way to enforce policies. By creating a ruleset that targets the main branch and requires the specific status checks, you can enforce the policy across the repository or organization. Crucially, rulesets have an explicit option to prevent even administrators from bypassing the rules, which meets the stated requirement.

  6. Question 6

    Q6

    A developer working on a public open-source project receives a Dependabot alert for a high-severity vulnerability in a transitive dependency. However, there is no direct patch available for the vulnerable package yet. What is the most appropriate first step for the developer to take?

    Show answer & explanation

    Correct answer: C

    For transitive dependencies, a direct patch for the sub-dependency may not exist or be the correct solution. The proper approach is to identify which direct dependency in the manifest file (e.g., package.json) is responsible for including the vulnerable package. Often, updating this top-level dependency to a newer version will, in turn, pull in a non-vulnerable version of the transitive dependency. Dependabot alerts often provide this context.

  7. Question 7

    Q7

    A company uses a proprietary, internally-developed static analysis tool that generates security reports in a custom JSON format. They want to integrate these results into the GitHub Security tab alongside findings from CodeQL. What is the correct sequence of steps to achieve this?

    Show answer & explanation

    Correct answer: A

    GitHub's code scanning feature is designed to ingest security results using the industry-standard Static Analysis Results Interchange Format (SARIF). To integrate a third-party tool, the output must first be converted into a valid SARIF v2.1.0 file. This transformed file can then be uploaded to the /code-scanning/sarifs API endpoint or using the github/codeql-action/upload-sarif action in a workflow. Direct upload of custom JSON is not supported.

  8. Question 8

    Q8

    What is the primary difference between how CodeQL analyzes a compiled language like C# and an interpreted language like Python?

    Show answer & explanation

    Correct answer: B

    The fundamental difference is that for compiled languages (C#, Java, C++, Go), CodeQL needs to observe the build process. It hooks into the compiler to understand how source files are related, how libraries are linked, and to build an accurate, queryable database representing the code's structure and data flow. For interpreted languages (Python, JavaScript, Ruby), there is no compilation step, so CodeQL can extract this information directly from the source code itself without needing to monitor a build.

  9. Question 9

    Q9

    The Security Overview dashboard provides a high-level view of an organization's security posture. Which information is available on this dashboard?

    Show answer & explanation

    Correct answer: B

    The Security Overview is a centralized dashboard that aggregates security alerts from all enabled features (Code Scanning, Secret Scanning, Dependabot) across the repositories in an organization. It allows security managers and administrators to quickly identify repositories with the most critical alerts and track overall risk trends without needing to inspect each repository individually.

  10. Question 10

    Q10

    A security team is reviewing a recent surge of secret scanning alerts. They notice many alerts are for secrets that have already been revoked. To improve their response efficiency, they want to prioritize alerts for secrets that are confirmed to be active. Which feature should they use?

    Show answer & explanation

    Correct answer: B

    Secret scanning validity checks are designed for this exact scenario. When a secret from a supported partner is detected, GitHub can optionally send the token to the provider's endpoint to verify if it is still active. This information is then displayed on the alert, allowing teams to filter for and prioritize the remediation of secrets that pose an immediate, confirmed risk.

Register free to unlock 10 more sample questions

Create a free account to continue with the rest of the GH-500 sample set.

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 232 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon