Skip to content

Configure and use Dependabot and Dependency Review Questions

Practice questions for Configure and use Dependabot and Dependency Review topic in GitHub Advanced Security. 71 questions covering this domain.

71 questions18 easy34 medium19 hard
Q1
medium

A team wants dependency review to fail only for high or critical vulnerabilities and also enforce license rules. What should they customize?

Q2
easy

Which feature shows dependency changes and vulnerability information on the Files changed tab of a pull request?

Q3
hard

After private registries are configured, some Dependabot version updates fail because manifest processing needs external code execution. Which setting...

Q4
easy

Which standard format does GitHub use when exporting an SBOM for a repository from the dependency graph?

Q5
medium

Why might a new low-risk Dependabot alert produce no email notification even though repository security notifications are enabled?

Q6
medium

What limitation applies to Dependabot alerts for GitHub Actions dependencies?

Q7
medium

A GitHub Actions workflow uses the dependency submission API to submit a repository snapshot. Which permission is required?

Q8
hard

Dependabot must update packages from a registry that is reachable only from an internal network. What should the team configure?

Q9
medium

An engineer wants to know which direct package introduced a vulnerable transitive dependency. Which dependency graph feature should they use?

Q10
medium

What must be enabled before dependency review becomes available for a repository?

Q11
medium

Which statement about grouped security updates is correct?

Q12
hard

A team wants control over exactly which Dependabot alerts should generate automated security-update pull requests instead of opening PRs for every ope...

Q13
easy

When Dependabot security updates is enabled and a patch is available, what does Dependabot attempt to do?

Q14
medium

By default, what happens when the dependency-review-action finds vulnerable packages?

Q15
hard

A team wants Dependabot to access private registries without storing long-lived credentials. Which approach should it use where supported?

Q16
medium

What is the purpose of the dependency submission API?

Q17
easy

When does GitHub generate new Dependabot alerts for a repository?

Q18
hard

A repository uses both dependency submission actions and the dependency-review-action in GitHub Actions. What is the safest way to avoid race conditio...

Q19
medium

After private registries are configured for Dependabot, what is the default behavior for external code execution during version updates?

Q20
hard

Which dependency data is a good candidate for the dependency submission API because static analysis often does not capture it?

Sign in to see all 71 questions

Create a free account to browse all questions — completely free during our launch phase.