GH-500 Sample Questions & Answers
Managing vulnerable dependencies with Dependabot takes the biggest share, ahead of CodeQL-based code scanning, configuring and customizing secret scanning, understanding GHAS features generally, and best practices for acting on the results.
Launch the full GH-500 simulator →Showing 10 of 20 free samples.
- Question 1Intermediate
Configure and use Dependabot and Dependency Review · Remedy a vulnerability from a Dependabot alert in the Security tab (could include updating or removing the dependency)
A developer working on a public open-source project receives a Dependabot alert for a high-severity vulnerability in a transitive dependency. However, there is no direct patch available for the vulnerable package yet. What is the most appropriate first step for the developer to take?
Show answer & explanation
Correct answer: C
For transitive dependencies, a direct patch for the sub-dependency may not exist or be the correct solution. The proper approach is to identify which direct dependency in the manifest file (e.g.,
package.json) is responsible for including the vulnerable package. Often, updating this top-level dependency to a newer version will, in turn, pull in a non-vulnerable version of the transitive dependency. Dependabot alerts often provide this context. - Question 2Advanced
Configure and use Code Scanning with CodeQL · Upload 3rd party SARIF results via the SARIF endpoint
A company uses a proprietary, internally-developed static analysis tool that generates security reports in a custom JSON format. They want to integrate these results into the GitHub Security tab alongside findings from CodeQL. What is the correct sequence of steps to achieve this?
Show answer & explanation
Correct answer: A
GitHub's code scanning feature is designed to ingest security results using the industry-standard Static Analysis Results Interchange Format (SARIF). To integrate a third-party tool, the output must first be converted into a valid SARIF v2.1.0 file. This transformed file can then be uploaded to the
/code-scanning/sarifsAPI endpoint or using thegithub/codeql-action/upload-sarifaction in a workflow. Direct upload of custom JSON is not supported. - Question 3Intermediate
Describe GitHub Advanced Security best practices, results, and how to take corrective measures · Describe how CodeQL analyzes code and produces results, including differences between compiled and interpreted language
What is the primary difference between how CodeQL analyzes a compiled language like C# and an interpreted language like Python?
Show answer & explanation
Correct answer: B
The fundamental difference is that for compiled languages (C#, Java, C++, Go), CodeQL needs to observe the build process. It hooks into the compiler to understand how source files are related, how libraries are linked, and to build an accurate, queryable database representing the code's structure and data flow. For interpreted languages (Python, JavaScript, Ruby), there is no compilation step, so CodeQL can extract this information directly from the source code itself without needing to monitor a build.
- Question 4Beginner
Describe the GHAS security features and functionality · Describe the features and benefits of Security Overview
The Security Overview dashboard provides a high-level view of an organization's security posture. Which information is available on this dashboard?
Show answer & explanation
Correct answer: B
The Security Overview is a centralized dashboard that aggregates security alerts from all enabled features (Code Scanning, Secret Scanning, Dependabot) across the repositories in an organization. It allows security managers and administrators to quickly identify repositories with the most critical alerts and track overall risk trends without needing to inspect each repository individually.
- Question 5Intermediate
Configure and use secret scanning · Describe validity checks
A security team is reviewing a recent surge of secret scanning alerts. They notice many alerts are for secrets that have already been revoked. To improve their response efficiency, they want to prioritize alerts for secrets that are confirmed to be active. Which feature should they use?
Show answer & explanation
Correct answer: B
Secret scanning validity checks are designed for this exact scenario. When a secret from a supported partner is detected, GitHub can optionally send the token to the provider's endpoint to verify if it is still active. This information is then displayed on the alert, allowing teams to filter for and prioritize the remediation of secrets that pose an immediate, confirmed risk.
- Question 6Beginner
Configure and use Dependabot and Dependency Review · Describe the difference between Dependabot and Dependency Review
A software development team is building a new application and wants to ensure that they are not using any dependencies with known security vulnerabilities from the very beginning. Which GHAS feature should be configured to provide feedback directly within a pull request about the security impact of adding or updating dependencies?
Show answer & explanation
Correct answer: B
Dependency Review is the feature specifically designed to analyze dependency changes within a pull request. It shows a diff of the dependencies, highlighting any new vulnerabilities being introduced, changes in licenses, and other critical information. This allows developers to assess the security impact before merging new code. Dependabot alerts, in contrast, scan the existing dependencies in a repository and raise alerts on the Security tab, but do not provide this proactive, in-PR diff view.
- Question 7Intermediate
Configure and use Code Scanning with CodeQL · Follow the data flow through code using the show paths experience
When reviewing a code scanning alert, a developer uses the 'Show paths' feature. What critical information does this feature provide for vulnerability analysis?
Show answer & explanation
Correct answer: C
The 'Show paths' feature is a powerful data-flow analysis tool within CodeQL alerts. For vulnerabilities like SQL injection or cross-site scripting, it visually traces the journey of tainted data from its entry point (the 'source,' e.g., an HTTP request) through the application to the point where it's used unsafely (the 'sink,' e.g., a database query). This helps developers understand the root cause and fix it effectively.
- Question 8Intermediate
Configure and use Dependabot and Dependency Review · Create a Dependabot Rule to auto-dismiss low severity alerts until a patch is available
An organization has a policy to automatically dismiss any Dependabot alert with a 'low' or 'moderate' severity for which a patch is not yet available. The goal is to reduce noise while ensuring high-severity alerts are always visible. Which feature should be used to automate this process?
Show answer & explanation
Correct answer: C
Dependabot rules are the native feature designed for this type of automation. An administrator can create a rule that targets specific alert severities (e.g., 'low', 'moderate') and has a condition to only act if a patch is not available (
has_patch: false). The action can then be set to 'auto-dismiss'. This provides a declarative, no-code way to implement the desired policy. - Question 9Intermediate
Configure and use Code Scanning with CodeQL · Choose a triggering event for a given development pattern (for example, in a pull request and for specific files)
A team has configured a CodeQL workflow to run on a schedule every Monday. They also want the scan to run automatically whenever code is pushed to any branch whose name starts with
release/. Whichonkey configuration in the workflow file is required to achieve this?Show answer & explanation
Correct answer: A
The
onkey in a GitHub Actions workflow file defines the events that trigger the workflow. To run on a schedule, you use theschedulekey with acronexpression. To run on pushes to specific branches, you use thepushkey with abranchesfilter. The patternrelease/*correctly matches any branch starting withrelease/. - Question 10Beginner
Configure and use Dependabot and Dependency Review · Describe what a Software Bill of Materials (SBOM) is, and the SBOM format used by GitHub
An organization's security policy requires a Software Bill of Materials (SBOM) to be generated for every production release. The SBOM must be in the SPDX format. Which GitHub feature natively supports the generation and export of this information?
Show answer & explanation
Correct answer: A
The Dependency Graph is the feature that analyzes a repository's manifest and lock files to determine all of its dependencies. GitHub allows you to export the data from the dependency graph as a Software Bill of Materials (SBOM) in the industry-standard SPDX format. This can be done via the UI or the REST API.
Ready for the real thing?
The full GH-500 simulator has every exam-style question, timed mode, and instant scoring.