Microsoft GH-500 - GitHub Advanced Security Exam
Where can you find a deleted line of code that contained a secret value?
After investigating a code scanning alert related to injection, you determine that the input is properly sanitized using custom logic. What should be your next step?
Which of the following tasks can be performed by a security team as a proactive measure to help address secret scanning alerts? (Each answer presents a complete solution. Choose two.)
How would you build your code within the CodeQL analysis workflow? (Each answer presents a complete solution. Choose two.)​
Which of the following steps should you follow to integrate CodeQL into a third-party continuous integration system? (Each answer presents part of the solution. Choose three.)
What do you need to do before you can define a custom pattern for a repository?​
Which of the following workflow events would trigger a dependency review? (Each answer presents a complete solution. Choose two.)​
When configuring code scanning with CodeQL, what are your options for specifying additional queries? (Each answer presents part of the solution. Choose two.)
As a developer with write access, you navigate to a code scanning alert in your repository. When will GitHub close this alert?
Which CodeQL query suite provides queries of lower severity than the default query suite?