Exit demo GH-500 GitHub Advanced Security PDF format · free preview

Microsoft GH-500 - Questions & Answers

Free preview · every answer includes a full explanation

Product page: https://prepkeys.com/gh-500.html

Question 1
Multiple choice

Which two query languages can CodeQL analyze simultaneously in a multi-language repository? (Choose two.)

A.

Java

B.

Python

C.

PowerShell

D.

Rust

E.

Go

Question 2
Single choice

Which event triggers CodeQL analysis by default?

A.

workflow_dispatch

B.

push and pull_request

C.

repository_dispatch

D.

schedule only

Question 3
Single choice

You must ensure all repositories within an organization have Code Scanning enabled.

What's the best approach?

A.

Apply an organization-level security policy

B.

Create a repository secret

C.

Configure CODEOWNERS

D.

Enable Dependabot alerts

Question 4
Single choice

Where can you download the full SARIF results of a CodeQL run?

A.

Under Actions tab workflow run summary Artifacts

B.

Security Code scanning alerts

C.

Settings Developer tools

D.

CodeQL CLI

Question 5
Single choice

Which command allows you to analyze a local repository using CodeQL CLI?

A.

codeql run analysis

B.

codeql database analyze

C.

codeql scan start

D.

codeql analyze repo

Question 6
Single choice

A secret scanning alert should be closed as "used in tests" when a secret is:

A.

in a test file.

B.

solely used for tests.

C.

in the readme.md file.

D.

not a secret in the production environment.

Question 7
Single choice

What happens when you enable secret scanning on a private repository?

A.

Repository administrators can view Dependabot alerts.

B.

Dependency review, secret scanning, and code scanning are enabled.

C.

Your team is subscribed to security alerts.

D.

GitHub performs a read-only analysis on the repository.

Question 8
Single choice

Which of the following statements best describes secret scanning push protection?

A.

Buttons for sensitive actions in the GitHub UI are disabled.

B.

Commits that contain secrets are blocked before code is added to the repository.

C.

Users need to reply to a 2FA challenge before any push events.

D.

Secret scanning alerts must be closed before a branch can be merged into the repository.

Question 9
Single choice

What is a security policy?

A.

a security alert issued to a community in response to a vulnerability

B.

a file in a GitHub repository that provides instructions to users about how to report a security vulnerability

C.

an alert about dependencies that are known to contain security vulnerabilities

D.

an automatic detection of security vulnerabilities and coding errors in new or modified code

Question 10
Single choice

Which of the following information can be found in a repository's Security tab?

A.

number of alerts per GHAS feature

B.

GHAS settings

C.

access management

D.

two-factor authentication (2FA) options

Showing 10 of 133 questions · Unlock the full set