Summer Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: pass65

Pass the Microsoft GitHub Administrator GH-500 Questions and answers with ValidTests

Exam GH-500 All Questions
Exam GH-500 Premium Access

View all detail and faqs for the GH-500 exam

Viewing page 1 out of 3 pages
Viewing questions 1-10 out of questions
Questions # 1:

In a private repository, what minimum requirements does GitHub need to generate a dependency graph? (Each answer presents part of the solution. Choose two.)​

Options:

A.

Read-only access to all the repository's files

B.

Dependency graph enabled at the organization level for all new private repositories

C.

Write access to the dependency manifest and lock files for an enterprise

D.

Read-only access to the dependency manifest and lock files for a repository​

Expert Solution
Questions # 2:

You are managing code scanning alerts for your repository. You receive an alert highlighting a problem with data flow. What do you click for additional context on the alert?​

Options:

A.

Show paths

B.

Security

C.

Code scanning alerts​

Expert Solution
Questions # 3:

What is a security policy?

Options:

A.

An automatic detection of security vulnerabilities and coding errors in new or modified code

B.

A security alert issued to a community in response to a vulnerability

C.

A file in a GitHub repository that provides instructions to users about how to report a security vulnerability

D.

An alert about dependencies that are known to contain security vulnerabilities

Expert Solution
Questions # 4:

As a repository owner, you want to receive specific notifications, including security alerts, for an individual repository. Which repository notification setting should you use?

Options:

A.

Ignore

B.

Participating and @mentions

C.

All Activity

D.

Custom

Expert Solution
Questions # 5:

Which of the following options would close a Dependabot alert?

Options:

A.

Creating a pull request to resolve the vulnerability that will be approved and merged

B.

Viewing the Dependabot alert on the Dependabot alerts tab of your repository

C.

Viewing the dependency graph

D.

Leaving the repository in its current state

Expert Solution
Questions # 6:

Assuming that no custom Dependabot behavior is configured, who has the ability to merge a pull request created via Dependabot security updates?​

Options:

A.

An enterprise administrator

B.

A user who has write access to the repository

C.

A user who has read access to the repository

D.

A repository member of an enterprise organization​

Expert Solution
Questions # 7:

When using the advanced CodeQL code scanning setup, what is the name of the workflow file?​

Options:

A.

codeql-config.yml

B.

codeql-scan.yml

C.

codeql-workflow.yml

D.

codeql-analysis.yml

Expert Solution
Questions # 8:

A secret scanning alert should be closed as "used in tests" when a secret is:

Options:

A.

In the readme.md file.

B.

In a test file.

C.

Solely used for tests.

D.

Not a secret in the production environment.

Expert Solution
Questions # 9:

Where can you view code scanning results from CodeQL analysis?

Options:

A.

The repository's code scanning alerts

B.

A CodeQL database

C.

A CodeQL query pack

D.

At Security advisories

Expert Solution
Questions # 10:

How would you build your code within the CodeQL analysis workflow? (Each answer presents a complete solution. Choose two.)​

Options:

A.

Upload compiled binaries.

B.

Use CodeQL's init action.

C.

Ignore paths.

D.

Implement custom build steps.

E.

Use jobs.analyze.runs-on.

F.

Use CodeQL's autobuild action.

Expert Solution
Viewing page 1 out of 3 pages
Viewing questions 1-10 out of questions