You need to run code scanning when files are modified in a specific directory. Which option can be used to complete line 3 in the workflow fragment below?
1. on:
2. push:
3.
Which of the following secret scanning features can verify whether a secret is still active?
Which of the following dependencies could trigger a Dependabot alert? (Each answer presents a complete solution. Choose two.)
You are configuring code scanning with CodeQL. What is one impact of using a language matrix in your workflow?
Which of the following workflow events would trigger a dependency review? (Each answer presents a complete solution. Choose two.)
Which patterns are secret scanning validity checks available to?
You are tasked with filtering queries in a CodeQL query suite. Which metadata tag matches on the last path component?
Who can fix a code scanning alert on a private repository?
You are a maintainer of a repository and Dependabot notifies you of a vulnerability. Where could the vulnerability have been disclosed? (Each answer presents part of the solution. Choose two.)
Which of the following formats are used to describe a code scanning alert from CodeQL?
Assuming that no custom patterns are configured, what type of secret is detected by secret scanning?
In a private repository, what minimum requirements does GitHub need to generate a dependency graph? (Each answer presents part of the solution. Choose two.)
If notification and alert recipients are not customized, which users receive notifications about new Dependabot alerts in an affected repository?
What is the first step you should take to fix an alert in secret scanning?
What happens when you disable secret scanning for a GitHub organization?
Which details do you have to provide to create a custom pattern for secret scanning? (Each answer presents part of the solution. Choose two.)
Secret scanning will scan:
You want to specify a CodeQL configuration file for a GitHub Actions workflow. Which input to the init step in the CodeQL action do you use to pass the path of the configuration file?
By default, who will receive an email when a secret has been detected in a repository? (Each answer presents a complete solution. Choose two.)
Which of the following features can be used to enforce passing status checks for code scanning and dependency review workflows?
How would you build your code within the CodeQL analysis workflow? (Each answer presents a complete solution. Choose two.)
Which of the following statements most accurately describes push protection for secret scanning custom patterns?
Which GitHub Advanced Security options are available under the Security section of the GitHub Enterprise Server Management Console? (Each answer presents part of the solution. Choose two.)
What are Dependabot security updates?
A colleague ignores a code scanning alert. What are the implications of the colleague's action? (Each answer presents part of the solution. Choose three.)
Where can you use CodeQL analysis for code scanning? (Each answer presents part of the solution. Choose two.)
You are managing code scanning alerts for your repository. You receive an alert highlighting a problem with data flow. What do you click for additional context on the alert?
Using advanced setup, which code scanning configuration would help detect vulnerabilities before they are added to a shared branch?
Assuming there is no custom Dependabot behavior configured, where possible, what does Dependabot do after sending an alert about a vulnerable dependency in a repository?
As a repository administrator, you can enable secret scanning on:
Which of the following options would close a Dependabot alert?
Your security team requested that you enable the dependency graph. What happens when you enable this feature for your repository?
When using CodeQL, what extension stores query suite definitions?
Which features are part of GitHub Advanced Security in the context of GitHub Enterprise? (Each correct answer presents part of the solution. Choose two.)
The autobuild step in the CodeQL workflow has failed. What should you do?
Which Dependabot configuration fields are required? (Each answer presents part of the solution. Choose three.)
Which of the following Watch settings could you use to get Dependabot alert notifications? (Each answer presents part of the solution. Choose two.)