Microsoft GH-500 - GitHub Advanced Security Exam
Which of the following features can be used to enforce passing status checks for code scanning and dependency review workflows?
Which Dependabot configuration fields are required? (Each answer presents part of the solution. Choose three.)
What kind of repository permissions do you need to request a Common Vulnerabilities and Exposures (CVE) identification number for a security advisory?​
As a repository owner, you do not want to run a GitHub Actions workflow when changes are made to any .txt or markdown files. How would you adjust the event trigger for a pull request that targets the main branch? (Each answer presents part of the solution. Choose three.)
on:
pull_request:
branches: [main]
What is the best method to ensure all new code is scanned for vulnerabilities?
Which of the following is the most complete method for Dependabot to find vulnerabilities in third-party dependencies?
An organization owner can give view access to Dependabot alerts to which type of user?
What is the first step you should take to fix an alert in secret scanning?
Where can you remove access to GitHub Advanced Security features for an individual repository in an organization? (Each answer presents part of the solution. Choose two.)
Which of the following secret scanning features can verify whether a secret is still active?
