75only - Ends in 0d 00h 00m 00s - Coupon code = 75only

Pass the Microsoft GitHub Administrator GH-500 Questions and answers with Dumpstech

Exam GH-500 Premium Access

View all detail and faqs for the GH-500 exam

Practice at least 50% of the questions to maximize your chances of passing.
Viewing page 1 out of 4 pages
Viewing questions 1-10 out of questions
Questions # 1:

Which of the following statements most accurately describes push protection for secret scanning custom patterns?​

Options:

A.

Push protection must be enabled for all, or none, of a repository's custom patterns.

B.

Push protection is an opt-in experience for each custom pattern.

C.

Push protection is not available for custom patterns.

D.

Push protection is enabled by default for new custom patterns.​

Questions # 2:

You are tasked with filtering queries in a CodeQL query suite. Which metadata tag matches on the last path component?

Options:

A.

query path

B.

tags contain all

C.

query filename

D.

tags contain

Questions # 3:

A secret scanning alert should be closed as "used in tests" when a secret is:

Options:

A.

In the readme.md file.

B.

In a test file.

C.

Solely used for tests.

D.

Not a secret in the production environment.

Questions # 4:

Assuming dependabot.yml does not exist in the repository, how many reviewers would Dependabot automatically assign to an open pull request?

Options:

A.

0

B.

1

C.

2

D.

3

Questions # 5:

Assuming that notification and alert recipients are not customized, what does GitHub do when it identifies a vulnerable dependency in a repository where Dependabot alerts are enabled? (Each answer presents part of the solution. Choose two.)​

Options:

A.

It generates a Dependabot alert and displays it on the Security tab for the repository.

B.

It notifies the repository administrators about the new alert.

C.

It generates Dependabot alerts by default for all private repositories.

D.

It consults with a security service and conducts a thorough vulnerability review.​

Questions # 6:

In a private repository, what minimum requirements does GitHub need to generate a dependency graph? (Each answer presents part of the solution. Choose two.)​

Options:

A.

Read-only access to all the repository's files

B.

Dependency graph enabled at the organization level for all new private repositories

C.

Write access to the dependency manifest and lock files for an enterprise

D.

Read-only access to the dependency manifest and lock files for a repository​

Questions # 7:

When using the advanced CodeQL code scanning setup, what is the name of the workflow file?​

Options:

A.

codeql-config.yml

B.

codeql-scan.yml

C.

codeql-workflow.yml

D.

codeql-analysis.yml

Questions # 8:

You are a maintainer of a repository and Dependabot notifies you of a vulnerability. Where could the vulnerability have been disclosed? (Each answer presents part of the solution. Choose two.)​

Options:

A.

In the National Vulnerability Database

B.

In the dependency graph

C.

In security advisories reported on GitHub

D.

In manifest and lock files

Questions # 9:

Where can you find the vulnerable dependencies that GitHub detected in your repository?

Options:

A.

In Dependabot alerts

B.

In secret scanning alerts

C.

In security advisories

D.

In code scanning alerts

Questions # 10:

As a repository owner, you want to receive specific notifications, including security alerts, for an individual repository. Which repository notification setting should you use?

Options:

A.

Ignore

B.

Participating and @mentions

C.

All Activity

D.

Custom

Viewing page 1 out of 4 pages
Viewing questions 1-10 out of questions