Pre-Winter Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: save70

Microsoft GH-500 Questions Answers

Page: 3 / 9
Total 125 questions

GitHub Advanced Security Exam Questions and Answers

Question 9

You are a maintainer of a repository and Dependabot notifies you of a vulnerability. Where could the vulnerability have been disclosed? (Each answer presents part of the solution. Choose two.)​

Options:

A.

In the National Vulnerability Database

B.

In the dependency graph

C.

In security advisories reported on GitHub

D.

In manifest and lock files

Question 10

Which of the following formats are used to describe a code scanning alert from CodeQL?

Options:

A.

Common Weakness Enumeration (CWE)

B.

Vulnerability Exploitability eXchange (VEX)

C.

Common Vulnerabilities and Exposures (CVE)

D.

GitHub Security Advisory (GHSA)

Question 11

Assuming that no custom patterns are configured, what type of secret is detected by secret scanning?

Options:

A.

Usernames

B.

Personally Identifiable Information (PII)

C.

Private keys

D.

Sealed boxes

Question 12

In a private repository, what minimum requirements does GitHub need to generate a dependency graph? (Each answer presents part of the solution. Choose two.)​

Options:

A.

Read-only access to all the repository's files

B.

Dependency graph enabled at the organization level for all new private repositories

C.

Write access to the dependency manifest and lock files for an enterprise

D.

Read-only access to the dependency manifest and lock files for a repository​

Page: 3 / 9
Total 125 questions