Weekend Special Sale 75% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: sale75best

Free Microsoft GH-500 Practice Exam with Questions & Answers | Set: 2

Questions 11

Which of the following tasks can be performed by a security team as a proactive measure to help address secret scanning alerts? (Each answer presents a complete solution. Choose two.)

Options:
A.

Dismiss alerts that are older than 90 days.

B.

Configure a webhook to monitor for secret scanning alert events.

C.

Enable system for cross-domain identity management (SCIM) provisioning for the enterprise.

D.

Document alternatives to storing secrets in the source code.

Microsoft GH-500 Premium Access
Questions 12

What is required to trigger code scanning on a specified branch?

Options:
A.

The repository must be private.

B.

Secret scanning must be enabled on the repository.

C.

Developers must actively maintain the repository.

D.

The workflow file must exist in that branch.

Questions 13

How many alerts are created when two instances of the same secret value are in the same repository?

Options:
A.

1

B.

2

C.

3

D.

4

Questions 14

You are configuring code scanning with CodeQL. What is one impact of using a language matrix in your workflow?

Options:
A.

CodeQL excludes alerts for those dependencies specified in the language matrix.

B.

CodeQL is configured to run analysis sequentially.

C.

You can use the languages parameter under the init action.

D.

CodeQL will only analyze the languages in the matrix.

Questions 15

Which of the following options are code scanning application programming interface (API) endpoints? (Each answer presents part of the solution. Choose two.)

Options:
A.

List all open code scanning alerts for the default branch

B.

Modify the severity of an open code scanning alert

C.

Get a single code scanning alert

D.

Delete all open code scanning alerts

Questions 16

Which syntax in a query suite tells CodeQL to look for one or more specified .ql files?

Options:
A.

query

B.

qlpack

C.

qls

Questions 17

You want to specify a CodeQL configuration file for a GitHub Actions workflow. Which input to the init step in the CodeQL action do you use to pass the path of the configuration file?

Options:
A.

config-file

B.

source-root

C.

db-location

D.

queries

Questions 18

What is the scope of the Enable all setting for Dependabot alerts at the organization level?

Options:
A.

Private repositories where GitHub Advanced Security is also enabled

B.

Related features for public repositories

C.

All repositories

D.

Only private repositories

Questions 19

Assuming that default security and analysis settings have not been changed at the repository, organization, or enterprise level, which scenario would generate a dependency graph for the repository?

Options:
A.

When a public repository has a new dependency added to its manifest file

B.

When a private repository is forked to be used as a dependent

C.

When a public repository is forked to be used as a dependent

D.

When a private repository has a new dependency added to its manifest file

Questions 20

Assuming security and analysis features are not configured at the repository, organization, or enterprise level, secret scanning is enabled on:

Options:
A.

Public repositories

B.

All new repositories within your organization

C.

User-owned private repositories

D.

Private repositories

Exam Code: GH-500
Certification Provider: Microsoft
Exam Name: GitHub Advanced Security Exam
Last Update: Oct 5, 2026
Questions: 125