Weekend Special Sale 75% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: sale75best

Free Microsoft GH-500 Practice Exam with Questions & Answers | Set: 4

Questions 31

What YAML syntax do you use to exclude certain files from secret scanning?

Options:
A.

decrypt_secret.sh

B.

paths-ignore:

C.

branches-ignore:

D.

secret scanning.yml

Microsoft GH-500 Premium Access
Questions 32

Assuming that notification and alert recipients are not customized, what does GitHub do when it identifies a vulnerable dependency in a repository where Dependabot alerts are enabled? (Each answer presents part of the solution. Choose two.)​

Options:
A.

It generates a Dependabot alert and displays it on the Security tab for the repository.

B.

It notifies the repository administrators about the new alert.

C.

It generates Dependabot alerts by default for all private repositories.

D.

It consults with a security service and conducts a thorough vulnerability review.​

Questions 33

To be compatible with code scanning, what data format must third-party code scanning tools use for output?

Options:
A.

Static Analysis Results Interchange Format (SARIF)

B.

YAML

C.

ESLint

D.

ECMAScript

Questions 34

When using CodeQL, how does extraction for compiled languages work?

Options:
A.

By generating one language at a time

B.

By resolving dependencies to give an accurate representation of the codebase

C.

By monitoring the normal build process

D.

By running directly on the source code

Questions 35

What is the first step you should take to fix an alert in secret scanning?

Options:
A.

Archive the repository.

B.

Update your dependencies.

C.

Revoke the alert if the secret is still valid.

D.

Remove the secret in a commit to the main branch.

Questions 36

Which of the following features helps to prioritize secret scanning alerts that present an immediate risk?

Options:
A.

Non-provider patterns

B.

Push protection

C.

Custom pattern dry runs

D.

Secret validation

Questions 37

Which features are part of GitHub Advanced Security in the context of GitHub Enterprise? (Each correct answer presents part of the solution. Choose two.)

Options:
A.

Dependency review

B.

Dependency graph

C.

Security policy

D.

Secret scanning