75only - Ends in 0d 00h 00m 00s - Coupon code = 75only

Pass the Microsoft GitHub Administrator GH-500 Questions and answers with Dumpstech

Exam GH-500 Premium Access

View all detail and faqs for the GH-500 exam

Practice at least 50% of the questions to maximize your chances of passing.
Viewing page 2 out of 4 pages
Viewing questions 11-20 out of questions
Questions # 11:

You want to specify a CodeQL configuration file for a GitHub Actions workflow. Which input to the init step in the CodeQL action do you use to pass the path of the configuration file?

Options:

A.

config-file

B.

source-root

C.

db-location

D.

queries

Questions # 12:

As a repository owner, you do not want to run a GitHub Actions workflow when changes are made to any .txt or markdown files. How would you adjust the event trigger for a pull request that targets the main branch? (Each answer presents part of the solution. Choose three.)

    on:

    pull_request:

    branches: [main]

Options:

A.

- '/*.md'

B.

- '/*.txt'

C.

paths:

D.

paths-ignore:

E.

- 'docs/*.md'

Questions # 13:

If default code security settings have not been changed at the repository, organization, or enterprise level, which repositories receive Dependabot alerts?

Options:

A.

Repositories owned by an enterprise account

B.

Private repositories

C.

None

D.

Repositories owned by an organization

Questions # 14:

Where can you find a deleted line of code that contained a secret value?

Options:

A.

Insights

B.

Issues

C.

Commits

D.

Dependency graph

Questions # 15:

What classifications are used to categorize Dependabot alerts? (Each correct answer presents part of the solution. Choose three.)

Options:

A.

Static Application Security Testing (SAST)

B.

Exploit Prediction Scoring System (EPSS)

C.

Common Vulnerabilities and Exposures (CVE)

D.

GitHub Security Advisory ID (GHSA)

E.

Common Weakness Enumeration (CWE)

Questions # 16:

Assuming that default security and analysis settings have not been changed at the repository, organization, or enterprise level, which scenario would generate a dependency graph for the repository?

Options:

A.

When a public repository has a new dependency added to its manifest file

B.

When a private repository is forked to be used as a dependent

C.

When a public repository is forked to be used as a dependent

D.

When a private repository has a new dependency added to its manifest file

Questions # 17:

Which details do you have to provide to create a custom pattern for secret scanning? (Each answer presents part of the solution. Choose two.)

Options:

A.

The secret format

B.

The name of the pattern

C.

A list of repositories to scan

D.

Additional match requirements for the secret format

Questions # 18:

Which of the following statements best describes secret scanning push protection?​

Options:

A.

Commits that contain secrets are blocked before code is added to the repository.

B.

Secret scanning alerts must be closed before a branch can be merged into the repository.

C.

Buttons for sensitive actions in the GitHub UI are disabled.

D.

Users need to reply to a 2FA challenge before any push events.​

Questions # 19:

Which of the following options are code scanning application programming interface (API) endpoints? (Each answer presents part of the solution. Choose two.)

Options:

A.

List all open code scanning alerts for the default branch

B.

Modify the severity of an open code scanning alert

C.

Get a single code scanning alert

D.

Delete all open code scanning alerts

Questions # 20:

What is a security policy?

Options:

A.

An automatic detection of security vulnerabilities and coding errors in new or modified code

B.

A security alert issued to a community in response to a vulnerability

C.

A file in a GitHub repository that provides instructions to users about how to report a security vulnerability

D.

An alert about dependencies that are known to contain security vulnerabilities

Viewing page 2 out of 4 pages
Viewing questions 11-20 out of questions