Pre-Winter Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70track

Free Microsoft GH-500 Practice Exam with Questions & Answers | Set: 3

Questions 21

Which of the following statements most accurately describes push protection for secret scanning custom patterns?​

Options:
A.

Push protection must be enabled for all, or none, of a repository's custom patterns.

B.

Push protection is an opt-in experience for each custom pattern.

C.

Push protection is not available for custom patterns.

D.

Push protection is enabled by default for new custom patterns.​

Microsoft GH-500 Premium Access
Questions 22

Which of the following steps should you follow to integrate CodeQL into a third-party continuous integration system? (Each answer presents part of the solution. Choose three.)

Options:
A.

Process alerts

B.

Analyze code

C.

Upload scan results

D.

Install the CLI

E.

Write queries

Questions 23

What happens when you enable secret scanning on a private repository?

Options:
A.

Repository administrators can view Dependabot alerts.

B.

Your team is subscribed to security alerts.

C.

GitHub performs a read-only analysis on the repository.

D.

Dependency review, secret scanning, and code scanning are enabled.

Questions 24

You want to enforce an enterprise policy that allows repository administrators within all organizations to enable GitHub Advanced Security for their repositories. Which option should you choose for this policy?

Options:
A.

No policy

B.

Allow for all organizations

C.

Never allow

D.

Allow for selected organizations

Questions 25

In a private repository, what minimum requirements does GitHub need to generate a dependency graph? (Each answer presents part of the solution. Choose two.)​

Options:
A.

Read-only access to all the repository's files

B.

Dependency graph enabled at the organization level for all new private repositories

C.

Write access to the dependency manifest and lock files for an enterprise

D.

Read-only access to the dependency manifest and lock files for a repository​

Questions 26

Assuming that no custom Dependabot behavior is configured, who has the ability to merge a pull request created via Dependabot security updates?​

Options:
A.

An enterprise administrator

B.

A user who has write access to the repository

C.

A user who has read access to the repository

D.

A repository member of an enterprise organization​

Questions 27

What kind of repository permissions do you need to request a Common Vulnerabilities and Exposures (CVE) identification number for a security advisory?​

Options:
A.

Maintain

B.

Admin

C.

Triage

D.

Write​

Questions 28

A repository's dependency graph includes:

Options:
A.

Dependencies parsed from a repository's manifest and lock files.

B.

Annotated code scanning alerts from your repository's dependencies.

C.

A summary of the dependencies used in your organization's repositories.

D.

Dependencies from all your repositories.

Questions 29

By default, which role can enable Dependabot alerts?

Options:
A.

Repository administrators

B.

Repository maintainers

C.

Security analysts

D.

Outside collaborators

Questions 30

Which of the following secret scanning features can verify whether a secret is still active?

Options:
A.

Push protection

B.

Validity checks

C.

Branch protection

D.

Custom patterns