Free GH-500 Practice Test Questions and Answers (2026) | Cert Empire Practice Questions
Free preview: 20 questions.
Microsoft GH 500
Q: 1
– [Configure and Use Dependency Management]
What should you do after receiving an alert about a dependency added in a pull request?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 2
– [Configure and Use Secret Scanning]
What is a prerequisite to define a custom pattern for a repository?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 3
– [Configure and Use Dependency Management]
When does Dependabot alert you of a vulnerability in your software development process?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 4
– [Use Code Scanning with CodeQL]
Why should you dismiss a code scanning alert?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 5
– [Configure and Use Secret Scanning]
Which of the following is the best way to prevent developers from adding secrets to the repository?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 6
– [Configure and Use Secret Scanning]
What filter or sort settings can be used to prioritize the secret scanning alerts that present the most
risk?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 7
– [Use Code Scanning with CodeQL]
As a developer with write access, you navigate to a code scanning alert in your repository. When will
GitHub close this alert?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 8
– [Configure and Use Secret Scanning]
Assuming security and analysis features are not configured at the repository, organization, or
enterprise level, secret scanning is enabled on:
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 9
– [Describe the GHAS Security Features and Functionality]
Which of the following information can be found in a repository's Security tab?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 10
– [Configure and Use Secret Scanning]
Which of the following features helps to prioritize secret scanning alerts that present an immediate
risk?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 11
– [Configure and Use Dependency Management]
If notification and alert recipients are not customized, which users receive notifications about new
Dependabot alerts in an affected repository?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 12
– [Assessing Code Scanning Alerts]
You are managing code scanning alerts for your repository. You receive an alert highlighting a
problem with data flow. What do you click for additional context on the alert?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 13
– [Configure and Use Secret Scanning]
How many alerts are created when two instances of the same secret value are in the same
repository?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 14
– [Configure and Use Dependency Management]
Which security feature shows a vulnerable dependency in a pull request?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 15
– [Configure and Use Dependency Management]
In a private repository, what minimum requirements does GitHub need to generate a dependency
graph? (Each answer presents part of the solution. Choose two.)
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Question 1 of 20