Summer Special 60% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: bestdeal

Free GitHub GitHub-Advanced-Security Practice Exam with Questions & Answers

Questions 1

What filter or sort settings can be used to prioritize the secret scanning alerts that present the most risk?

Options:
A.

Sort to display the oldest first

B.

Sort to display the newest first

C.

Filter to display active secrets

D.

Select only the custom patterns

GitHub GitHub-Advanced-Security Premium Access
Questions 2

When using CodeQL, how does extraction for compiled languages work?

Options:
A.

By generating one language at a time

B.

By resolving dependencies to give an accurate representation of the codebase

C.

By monitoring the normal build process

D.

By running directly on the source code

Questions 3

Which of the following workflow events would trigger a dependency review? (Each answer presents a complete solution. Choose two.)​

Options:
A.

pull_request

B.

workflow_dispatch

C.

trigger

D.

commit

Questions 4

When using CodeQL, what extension stores query suite definitions?

Options:
A.

.yml

B.

.ql

C.

.qll

D.

.qls

Questions 5

What is the first step you should take to fix an alert in secret scanning?

Options:
A.

Archive the repository.

B.

Update your dependencies.

C.

Revoke the alert if the secret is still valid.

D.

Remove the secret in a commit to the main branch.

Questions 6

Which of the following tasks can be performed by a security team as a proactive measure to help address secret scanning alerts? (Each answer presents a complete solution. Choose two.)

Options:
A.

Dismiss alerts that are older than 90 days.

B.

Configure a webhook to monitor for secret scanning alert events.

C.

Enable system for cross-domain identity management (SCIM) provisioning for the enterprise.

D.

Document alternatives to storing secrets in the source code.

Questions 7

What is a security policy?

Options:
A.

An automatic detection of security vulnerabilities and coding errors in new or modified code

B.

A security alert issued to a community in response to a vulnerability

C.

A file in a GitHub repository that provides instructions to users about how to report a security vulnerability

D.

An alert about dependencies that are known to contain security vulnerabilities

Questions 8

Secret scanning will scan:​

Options:
A.

A continuous integration system.

B.

Any Git repository.

C.

The GitHub repository.

D.

External services.​

Questions 9

As a contributor, you discovered a vulnerability in a repository. Where should you look for the instructions on how to report the vulnerability?

Options:
A.

support.md

B.

readme.md

C.

contributing.md

D.

security.md

Questions 10

In a private repository, what minimum requirements does GitHub need to generate a dependencygraph? (Each answer presents part of the solution. Choose two.)​

Options:
A.

Read-only access to all the repository's files

B.

Dependency graph enabled at the organization level for all new private repositories

C.

Write access to the dependency manifest and lock files for an enterprise

D.

Read-only access to the dependency manifest and lock files for a repository​

Certification Provider: GitHub
Exam Name: GitHub Advanced Security GHAS Exam
Last Update: Jul 15, 2025
Questions: 75

GitHub Related Exams

How to pass GitHub GitHub-Foundations - GitHub FoundationsExam Exam

GitHub Free Exams

GitHub Free Exams