GitHub Advanced Security Questions and Answers
300 questions organized by topic with detailed explanations
GitHub
GH-500
300 questions
5 topics
Updated Jul 2026Describe the GHAS security features and functionality
46 questions12 easy23 medium11 hard~15% of exam
Configure and use secret scanning
44 questions11 easy21 medium12 hard~15% of exam
Configure and use Dependabot and Dependency Review
106 questions26 easy51 medium29 hard~35% of exam
A team wants dependency review to fail only for high or critical vulnerabilities and also enforce license rules. What sh...Which feature shows dependency changes and vulnerability information on the Files changed tab of a pull request?After private registries are configured, some Dependabot version updates fail because manifest processing needs external...
Configure and use Code Scanning with CodeQL
74 questions19 easy37 medium18 hard~25% of exam
Which built-in CodeQL query suite is designed to be more precise and return fewer false positives?What happens if a repository switches from advanced setup to default setup for CodeQL?An organization assigns a self-hosted runner to a repository that already uses code scanning default setup. What must be...
Describe GitHub Advanced Security best practices, results, and how to take corrective measures
30 questions10 easy18 medium2 hard~10% of exam
A developer accepts a Copilot Autofix suggestion for a code scanning alert. What should they verify before merging?A security lead wants to prevent hardcoded credentials from ever reaching repository history. Which control is the best ...What should be used for consistent compliance or auditing reports when security overview dashboard numbers might change ...
All Questions
| # | Question | Topic | Difficulty |
|---|---|---|---|
| 1 | A developer accepts a Copilot Autofix suggestion for a code scanning alert. What should they verify ... | Describe GitHub Advanced Security best practices, results, and how to take corrective measures | medium |
| 2 | A team wants dependency review to fail only for high or critical vulnerabilities and also enforce li... | Configure and use Dependabot and Dependency Review | medium |
| 3 | Which feature shows dependency changes and vulnerability information on the Files changed tab of a p... | Configure and use Dependabot and Dependency Review | easy |
| 4 | After private registries are configured, some Dependabot version updates fail because manifest proce... | Configure and use Dependabot and Dependency Review | hard |
| 5 | Who can view security data across all repositories in an organization from security overview? | Describe the GHAS security features and functionality | medium |
Sign in to see all 300 questions
Create a free account to browse the questions included with the free plan.
Ready to test your knowledge?
Take a full GitHub Advanced Security practice test with timed exam simulation.
Start Practice Test