Weekend Sale Special - 75% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: newyear

Microsoft GH-500 - GitHub Advanced Security Exam

Page: 1 / 4
Total 125 questions

What is the format of the GitHub security advisory form?

A.

A CVE Numbering Authority (CNA) description format

B.

A Dependabot alert sent to the affected repositories

C.

A form matching the MITRE database security advisory format

D.

A form matching the Common Vulnerabilities and Exposures (CVE) description format

Who can fix a code scanning alert on a private repository?​

A.

Users who have the Triage role within the repository

B.

Users who have Read permissions within the repository

C.

Users who have Write access to the repository

D.

Users who have the security manager role within the repository​

Assuming that notification settings and Dependabot alert recipients have not been customized, which user account setting should you use to get an alert when a vulnerability is detected in one of your repositories?

A.

Enable all in existing repositories

B.

Enable by default for new public repositories

C.

Enable all for Dependabot alerts

D.

Enable all for Dependency graph

By default, who will receive an email when a secret has been detected in a repository? (Each answer presents a complete solution. Choose two.)

A.

Security analyst

B.

User who committed the secret

C.

Users with the Admin repository role

D.

Users with the Write repository role

E.

Users with the Maintain repository role

When using CodeQL, how does extraction for compiled languages work?

A.

By generating one language at a time

B.

By resolving dependencies to give an accurate representation of the codebase

C.

By monitoring the normal build process

D.

By running directly on the source code

What should you do after receiving an alert about a dependency added in a pull request?

A.

Disable Dependabot alerts for all repositories owned by your organization

B.

Fork the branch and deploy the new fork

C.

Update the vulnerable dependencies before the branch is merged

D.

Deploy the code to your default branch

When does Dependabot alert you of a vulnerability in your software development process?

A.

When a pull request adding a vulnerable dependency is opened

B.

As soon as a vulnerable dependency is detected

C.

As soon as a pull request is opened by a contributor

D.

When Dependabot opens a pull request to update a vulnerable dependency

After defining a secret scanning custom pattern, what is the final step before publishing the pattern?

A.

Defining a custom pattern

B.

Enabling push protection

C.

Adding additional match requirements

D.

Performing a dry run

What do you need to do before you can define a custom pattern for a repository?​

A.

Provide a regular expression for the format of your secret pattern.

B.

Add a secret scanning custom pattern.

C.

Enable secret scanning on the repository.

D.

Provide match requirements for the secret format.​

Stack Overflow

You are a maintainer of a repository and Dependabot notifies you of a vulnerability. Where could the vulnerability have been disclosed? (Each answer presents part of the solution. Choose two.)​

A.

In the National Vulnerability Database

B.

In the dependency graph

C.

In security advisories reported on GitHub

D.

In manifest and lock files