View all detail and faqs for the GitHub-Advanced-Security exam
What is required to trigger code scanning on a specified branch?
What is a prerequisite to define a custom pattern for a repository?
Which of the following secret scanning features can verify whether a secret is still active?
As a contributor, you discovered a vulnerability in a repository. Where should you look for the instructions on how to report the vulnerability?
Assuming there is no custom Dependabot behavior configured, where possible, what does Dependabot do after sending an alert about a vulnerable dependency in a repository?
Which key is required in the update settings of the Dependabot configuration file?
What does code scanning do?
What kind of repository permissions do you need to request a Common Vulnerabilities and Exposures (CVE) identification number for a security advisory?
Which details do you have to provide to create a custom pattern for secret scanning? (Each answer presents part of the solution. Choose two.)
Which of the following steps should you follow to integrate CodeQL into a third-party continuous integration system? (Each answer presents part of the solution. Choose three.)