Microsoft GH-500 - GitHub Advanced Security Exam
What is the format of the GitHub security advisory form?
Who can fix a code scanning alert on a private repository?​
Assuming that notification settings and Dependabot alert recipients have not been customized, which user account setting should you use to get an alert when a vulnerability is detected in one of your repositories?
By default, who will receive an email when a secret has been detected in a repository? (Each answer presents a complete solution. Choose two.)
When using CodeQL, how does extraction for compiled languages work?
What should you do after receiving an alert about a dependency added in a pull request?
When does Dependabot alert you of a vulnerability in your software development process?
After defining a secret scanning custom pattern, what is the final step before publishing the pattern?
What do you need to do before you can define a custom pattern for a repository?​
You are a maintainer of a repository and Dependabot notifies you of a vulnerability. Where could the vulnerability have been disclosed? (Each answer presents part of the solution. Choose two.)​
