Weekend Sale Special - 75% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: newyear

Microsoft GH-500 - GitHub Advanced Security Exam

Page: 2 / 4
Total 125 questions

Which of the following features can be used to enforce passing status checks for code scanning and dependency review workflows?

A.

Security GuardRails

B.

Status enforcement

C.

Repository rulesets

D.

Insights

Which Dependabot configuration fields are required? (Each answer presents part of the solution. Choose three.)

A.

directory

B.

package-ecosystem

C.

milestone

D.

schedule.interval

E.

allow

What kind of repository permissions do you need to request a Common Vulnerabilities and Exposures (CVE) identification number for a security advisory?​

A.

Maintain

B.

Admin

C.

Triage

D.

Write​

As a repository owner, you do not want to run a GitHub Actions workflow when changes are made to any .txt or markdown files. How would you adjust the event trigger for a pull request that targets the main branch? (Each answer presents part of the solution. Choose three.)

    on:

    pull_request:

    branches: [main]

A.

- '/*.md'

B.

- '/*.txt'

C.

paths:

D.

paths-ignore:

E.

- 'docs/*.md'

What is the best method to ensure all new code is scanned for vulnerabilities?

A.

Add the extended suite.

B.

Configure code owners.

C.

Set up a security policy.

D.

Configure code scanning.

Which of the following is the most complete method for Dependabot to find vulnerabilities in third-party dependencies?

A.

Dependabot reviews manifest files in the repository

B.

CodeQL analyzes the code and raises vulnerabilities in third-party dependencies

C.

A dependency graph is created, and Dependabot compares the graph to the GitHub Advisory database

D.

The build tool finds the vulnerable dependencies and calls the Dependabot API

An organization owner can give view access to Dependabot alerts to which type of user?

A.

Members of a team with Read access to a different repository within the same organization

B.

Outside collaborators with Read access

C.

Members of a team with Write access to the repository

D.

Members of an enterprise unassigned to the repository

What is the first step you should take to fix an alert in secret scanning?

A.

Archive the repository.

B.

Update your dependencies.

C.

Revoke the alert if the secret is still valid.

D.

Remove the secret in a commit to the main branch.

Where can you remove access to GitHub Advanced Security features for an individual repository in an organization? (Each answer presents part of the solution. Choose two.)

A.

The enterprise's Settings tab

B.

The organization's Settings tab

C.

The repository's Settings tab

D.

The organization's Repository permissions

Which of the following secret scanning features can verify whether a secret is still active?

A.

Push protection

B.

Validity checks

C.

Branch protection

D.

Custom patterns