Pre-Winter Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: save70

Free Access Microsoft GH-500 New Release

Page: 8 / 9
Total 125 questions

GitHub Advanced Security Exam Questions and Answers

Question 29

Assuming there is no custom Dependabot behavior configured, where possible, what does Dependabot do after sending an alert about a vulnerable dependency in a repository?

Options:

A.

Creates a pull request to upgrade the vulnerable dependency to the minimum possible secure version

B.

Scans repositories for vulnerable dependencies on a schedule and adds those files to a manifest

C.

Constructs a graph of all the repository's dependencies and public dependents for the default branch

D.

Scans any push to all branches and generates an alert for each vulnerable repository

Question 30

As a repository administrator, you can enable secret scanning on:

Options:

A.

Current private repositories owned by your organization

B.

Current private repositories owned by users of your organization

C.

New user-owned private repositories created by users within your organization

D.

New private repositories created by users outside your organization

Question 31

Which of the following options would close a Dependabot alert?

Options:

A.

Creating a pull request to resolve the vulnerability that will be approved and merged

B.

Viewing the Dependabot alert on the Dependabot alerts tab of your repository

C.

Viewing the dependency graph

D.

Leaving the repository in its current state

Question 32

Your security team requested that you enable the dependency graph. What happens when you enable this feature for your repository?

Options:

A.

Admins of the repository will see dependency information in the dependency graph.

B.

Dependabot security updates create pull requests to upgrade those dependencies.

C.

New repositories will need to have dependency information enabled.

D.

GitHub generates Dependabot alerts for vulnerable dependencies.

Page: 8 / 9
Total 125 questions