Pre-Winter Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: save70

Free and Premium Microsoft GH-500 Dumps Questions Answers

Page: 1 / 9
Total 125 questions

GitHub Advanced Security Exam Questions and Answers

Question 1

You need to run code scanning when files are modified in a specific directory. Which option can be used to complete line 3 in the workflow fragment below?

1. on:

2. push:

3.

Options:

A.

**foo

B.

(

C.

?

D.

paths:

Buy Now
Question 2

Which of the following secret scanning features can verify whether a secret is still active?

Options:

A.

Push protection

B.

Validity checks

C.

Branch protection

D.

Custom patterns

Question 3

Which of the following dependencies could trigger a Dependabot alert? (Each answer presents a complete solution. Choose two.)

Options:

A.

Indirect dependencies explicitly declared in a lockfile

B.

Loose dependencies declared in a manifest

C.

Direct dependencies explicitly declared in a manifest

D.

Direct dependencies at 08:00 UTC

Question 4

You are configuring code scanning with CodeQL. What is one impact of using a language matrix in your workflow?

Options:

A.

CodeQL excludes alerts for those dependencies specified in the language matrix.

B.

CodeQL is configured to run analysis sequentially.

C.

You can use the languages parameter under the init action.

D.

CodeQL will only analyze the languages in the matrix.

Question 5

Which of the following workflow events would trigger a dependency review? (Each answer presents a complete solution. Choose two.)​

Options:

A.

pull_request

B.

workflow_dispatch

C.

trigger

D.

commit

Question 6

Which patterns are secret scanning validity checks available to?

Options:

A.

High entropy strings

B.

Custom patterns

C.

Partner patterns

D.

Push protection patterns

Question 7

You are tasked with filtering queries in a CodeQL query suite. Which metadata tag matches on the last path component?

Options:

A.

query path

B.

tags contain all

C.

query filename

D.

tags contain

Question 8

Who can fix a code scanning alert on a private repository?​

Options:

A.

Users who have the Triage role within the repository

B.

Users who have Read permissions within the repository

C.

Users who have Write access to the repository

D.

Users who have the security manager role within the repository​

Question 9

You are a maintainer of a repository and Dependabot notifies you of a vulnerability. Where could the vulnerability have been disclosed? (Each answer presents part of the solution. Choose two.)​

Options:

A.

In the National Vulnerability Database

B.

In the dependency graph

C.

In security advisories reported on GitHub

D.

In manifest and lock files

Question 10

Which of the following formats are used to describe a code scanning alert from CodeQL?

Options:

A.

Common Weakness Enumeration (CWE)

B.

Vulnerability Exploitability eXchange (VEX)

C.

Common Vulnerabilities and Exposures (CVE)

D.

GitHub Security Advisory (GHSA)

Question 11

Assuming that no custom patterns are configured, what type of secret is detected by secret scanning?

Options:

A.

Usernames

B.

Personally Identifiable Information (PII)

C.

Private keys

D.

Sealed boxes

Question 12

In a private repository, what minimum requirements does GitHub need to generate a dependency graph? (Each answer presents part of the solution. Choose two.)​

Options:

A.

Read-only access to all the repository's files

B.

Dependency graph enabled at the organization level for all new private repositories

C.

Write access to the dependency manifest and lock files for an enterprise

D.

Read-only access to the dependency manifest and lock files for a repository​

Question 13

If notification and alert recipients are not customized, which users receive notifications about new Dependabot alerts in an affected repository?

Options:

A.

Users with Write permissions to the repository

B.

Users with Admin privileges to the repository

C.

Users with Maintain privileges to the repository

D.

Users with Read permissions to the repository

Question 14

What is the first step you should take to fix an alert in secret scanning?

Options:

A.

Archive the repository.

B.

Update your dependencies.

C.

Revoke the alert if the secret is still valid.

D.

Remove the secret in a commit to the main branch.

Question 15

What happens when you disable secret scanning for a GitHub organization?

Options:

A.

Changes affect public repositories for your organization where GitHub Advanced Security is enabled.

B.

All GitHub Advanced Security features are disabled.

C.

Changes affect private repositories where GitHub Advanced Security is also enabled.

D.

Changes affect all repositories with GitHub Advanced Security disabled.

Question 16

Which details do you have to provide to create a custom pattern for secret scanning? (Each answer presents part of the solution. Choose two.)

Options:

A.

The secret format

B.

The name of the pattern

C.

A list of repositories to scan

D.

Additional match requirements for the secret format

Question 17

Secret scanning will scan:​

Options:

A.

A continuous integration system.

B.

Any Git repository.

C.

The GitHub repository.

D.

External services.​

Question 18

You want to specify a CodeQL configuration file for a GitHub Actions workflow. Which input to the init step in the CodeQL action do you use to pass the path of the configuration file?

Options:

A.

config-file

B.

source-root

C.

db-location

D.

queries

Question 19

By default, who will receive an email when a secret has been detected in a repository? (Each answer presents a complete solution. Choose two.)

Options:

A.

Security analyst

B.

User who committed the secret

C.

Users with the Admin repository role

D.

Users with the Write repository role

E.

Users with the Maintain repository role

Question 20

Which of the following features can be used to enforce passing status checks for code scanning and dependency review workflows?

Options:

A.

Security GuardRails

B.

Status enforcement

C.

Repository rulesets

D.

Insights

Question 21

How would you build your code within the CodeQL analysis workflow? (Each answer presents a complete solution. Choose two.)​

Options:

A.

Upload compiled binaries.

B.

Use CodeQL's init action.

C.

Ignore paths.

D.

Implement custom build steps.

E.

Use jobs.analyze.runs-on.

F.

Use CodeQL's autobuild action.

Question 22

Which of the following statements most accurately describes push protection for secret scanning custom patterns?​

Options:

A.

Push protection must be enabled for all, or none, of a repository's custom patterns.

B.

Push protection is an opt-in experience for each custom pattern.

C.

Push protection is not available for custom patterns.

D.

Push protection is enabled by default for new custom patterns.​

Question 23

Which GitHub Advanced Security options are available under the Security section of the GitHub Enterprise Server Management Console? (Each answer presents part of the solution. Choose two.)

Options:

A.

Secret scanning

B.

Code scanning

C.

Dependency review

D.

Dependabot version updates

Question 24

What are Dependabot security updates?

Options:

A.

Automated pull requests that help you update dependencies that have known vulnerabilities

B.

Automated pull requests that keep your dependencies updated, even when they don’t have any vulnerabilities

C.

Automated pull requests to update the manifest to the latest version of the dependency

D.

Compatibility scores to let you know whether updating a dependency could cause breaking changes to your project

Question 25

A colleague ignores a code scanning alert. What are the implications of the colleague's action? (Each answer presents part of the solution. Choose three.)

Options:

A.

A dangerous argument could be passed to functions.

B.

Data could be used insecurely.

C.

GitHub removes the alert after sixty days.

D.

Webhooks and the code scanning API remove the alert.

E.

Sensitive information could be leaked.

Question 26

Where can you use CodeQL analysis for code scanning? (Each answer presents part of the solution. Choose two.)

Options:

A.

In a third-party Git repository

B.

In a workflow

C.

In an external continuous integration (CI) system

D.

In the Files changed tab of the pull request

Question 27

You are managing code scanning alerts for your repository. You receive an alert highlighting a problem with data flow. What do you click for additional context on the alert?​

Options:

A.

Show paths

B.

Security

C.

Code scanning alerts​

Question 28

Using advanced setup, which code scanning configuration would help detect vulnerabilities before they are added to a shared branch?

Options:

A.

on:

issues:

B.

on:

pull_request:

C.

on:

schedule:

D.

on:

workflow_dispatch:

Question 29

Assuming there is no custom Dependabot behavior configured, where possible, what does Dependabot do after sending an alert about a vulnerable dependency in a repository?

Options:

A.

Creates a pull request to upgrade the vulnerable dependency to the minimum possible secure version

B.

Scans repositories for vulnerable dependencies on a schedule and adds those files to a manifest

C.

Constructs a graph of all the repository's dependencies and public dependents for the default branch

D.

Scans any push to all branches and generates an alert for each vulnerable repository

Question 30

As a repository administrator, you can enable secret scanning on:

Options:

A.

Current private repositories owned by your organization

B.

Current private repositories owned by users of your organization

C.

New user-owned private repositories created by users within your organization

D.

New private repositories created by users outside your organization

Question 31

Which of the following options would close a Dependabot alert?

Options:

A.

Creating a pull request to resolve the vulnerability that will be approved and merged

B.

Viewing the Dependabot alert on the Dependabot alerts tab of your repository

C.

Viewing the dependency graph

D.

Leaving the repository in its current state

Question 32

Your security team requested that you enable the dependency graph. What happens when you enable this feature for your repository?

Options:

A.

Admins of the repository will see dependency information in the dependency graph.

B.

Dependabot security updates create pull requests to upgrade those dependencies.

C.

New repositories will need to have dependency information enabled.

D.

GitHub generates Dependabot alerts for vulnerable dependencies.

Question 33

When using CodeQL, what extension stores query suite definitions?

Options:

A.

.yml

B.

.ql

C.

.qll

D.

.qls

Question 34

Which features are part of GitHub Advanced Security in the context of GitHub Enterprise? (Each correct answer presents part of the solution. Choose two.)

Options:

A.

Dependency review

B.

Dependency graph

C.

Security policy

D.

Secret scanning

Question 35

The autobuild step in the CodeQL workflow has failed. What should you do?

Options:

A.

Remove specific build steps.

B.

Compile the source code.

C.

Remove the autobuild step from your code scanning workflow and add specific build steps.

D.

Use CodeQL, which implicitly detects the supported languages in your code base.

Question 36

Which Dependabot configuration fields are required? (Each answer presents part of the solution. Choose three.)

Options:

A.

directory

B.

package-ecosystem

C.

milestone

D.

schedule.interval

E.

allow

Question 37

Which of the following Watch settings could you use to get Dependabot alert notifications? (Each answer presents part of the solution. Choose two.)

Options:

A.

The Custom setting

B.

The Participating and @mentions setting

C.

The All Activity setting

D.

The Ignore setting

Page: 1 / 9
Total 125 questions