Month End Special - 75% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: certbig75

GH-500 Exam Dumps - Microsoft GitHub Administrator Questions and Answers

Question # 24

After defining a secret scanning custom pattern, what is the final step before publishing the pattern?

Options:

A.

Defining a custom pattern

B.

Enabling push protection

C.

Adding additional match requirements

D.

Performing a dry run

Buy Now
Question # 25

What should you do after receiving an alert about a dependency added in a pull request?

Options:

A.

Disable Dependabot alerts for all repositories owned by your organization

B.

Fork the branch and deploy the new fork

C.

Update the vulnerable dependencies before the branch is merged

D.

Deploy the code to your default branch

Buy Now
Question # 26

What does a CodeQL database of your repository contain?​

Options:

A.

A build for Go projects to set up the project

B.

A build of the code and extracted data

C.

Build commands for C/C++, C#, and Java

D.

A representation of all of the source code​

GitHub

Agentic AI for AppSec Teams

Buy Now
Question # 27

After investigating a code scanning alert related to injection, you determine that the input is properly sanitized using custom logic. What should be your next step?

Options:

A.

Draft a pull request to update the open-source query.

B.

Ignore the alert.

C.

Open an issue in the CodeQL repository.

D.

Dismiss the alert with the reason "false positive."

Buy Now
Question # 28

Which Dependabot configuration fields are required? (Each answer presents part of the solution. Choose three.)

Options:

A.

directory

B.

package-ecosystem

C.

milestone

D.

schedule.interval

E.

allow

Buy Now
Question # 29

An organization owner can give view access to Dependabot alerts to which type of user?

Options:

A.

Members of a team with Read access to a different repository within the same organization

B.

Outside collaborators with Read access

C.

Members of a team with Write access to the repository

D.

Members of an enterprise unassigned to the repository

Buy Now
Question # 30

Which of the following information can be found in a repository's Security tab?

Options:

A.

Number of alerts per GHAS feature

B.

Two-factor authentication (2FA) options

C.

Access management

D.

GHAS settings

Buy Now
Question # 31

Assuming that no custom Dependabot behavior is configured, who has the ability to merge a pull request created via Dependabot security updates?​

Options:

A.

An enterprise administrator

B.

A user who has write access to the repository

C.

A user who has read access to the repository

D.

A repository member of an enterprise organization​

Buy Now
Question # 32

Assuming that no custom patterns are configured, what type of secret is detected by secret scanning?

Options:

A.

Usernames

B.

Personally Identifiable Information (PII)

C.

Private keys

D.

Sealed boxes

Buy Now
Question # 33

Which GitHub Advanced Security options are available under the Security section of the GitHub Enterprise Server Management Console? (Each answer presents part of the solution. Choose two.)

Options:

A.

Secret scanning

B.

Code scanning

C.

Dependency review

D.

Dependabot version updates

Buy Now
Exam Code: GH-500
Exam Name: GitHub Advanced Security Exam
Last Update: Sep 30, 2026
Questions: 125
GH-500 pdf

GH-500 PDF

$23.75  $94.99
GH-500 Engine

GH-500 Testing Engine

$27.5  $109.99
GH-500 PDF + Engine

GH-500 PDF + Testing Engine

$36.25  $144.99