Weekend Sale Special - 75% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: newyear

Microsoft GH-500 - GitHub Advanced Security Exam

Page: 3 / 4
Total 125 questions

You have enabled security updates for a repository. When does GitHub mark a Dependabot alert as resolved for that repository?

A.

When Dependabot creates a pull request to update dependencies

B.

When you dismiss the Dependabot alert

C.

When the pull request checks are successful

D.

When you merge a pull request that contains a security update

Your security team requested that you enable the dependency graph. What happens when you enable this feature for your repository?

A.

Admins of the repository will see dependency information in the dependency graph.

B.

Dependabot security updates create pull requests to upgrade those dependencies.

C.

New repositories will need to have dependency information enabled.

D.

GitHub generates Dependabot alerts for vulnerable dependencies.

In the pull request, how can developers avoid adding new dependencies with known vulnerabilities?

A.

Enable Dependabot alerts.

B.

Add Dependabot rules.

C.

Add a workflow with the dependency review action.

D.

Enable Dependabot security updates.

By default, which role can enable Dependabot alerts?

A.

Repository administrators

B.

Repository maintainers

C.

Security analysts

D.

Outside collaborators

Which of the following workflow events would trigger a dependency review? (Each answer presents a complete solution. Choose two.)​

A.

pull_request

B.

workflow_dispatch

C.

trigger

D.

commit

What happens when you remove someone's access to a private repository?

A.

Local clones of the private repository are deleted.

B.

Team access to a private repository is revoked.

C.

Their forks of that private repository are deleted.

D.

Confidential information is deleted.

By default, what is the minimum role needed to bypass push protection in a repository?

A.

Maintain

B.

Write

C.

Admin

D.

Triage

When using CodeQL, what extension stores query suite definitions?

A.

.yml

B.

.ql

C.

.qll

D.

.qls

What is a benefit of using a custom CodeQL configuration file?

A.

It specifies a token that has access to the private repository.

B.

It automatically selects the package to use.

C.

It allows configuration options for multiple repositories in a single place.

D.

It disables packs from running the default query suite.

You want to enforce an enterprise policy that allows repository administrators within all organizations to enable GitHub Advanced Security for their repositories. Which option should you choose for this policy?

A.

No policy

B.

Allow for all organizations

C.

Never allow

D.

Allow for selected organizations