Free Practice Questions for GitHub Advanced Security (GH-500) Certification
Study with 345 exam-style practice questions designed to help you prepare for the GitHub Advanced Security (GH-500).
Start Practicing
All Domains
Practice with randomly mixed questions from all topics
Domain Mode
Practice questions from a specific topic area
Quiz History
Exam Details
Key information about GitHub Advanced Security (GH-500)
- Multiple choice
- Ordering
- Matching
Candidates with experience using GitHub Advanced Security (GHAS) to secure code, secrets, and dependencies across the software development lifecycle, familiar with GitHub fundamentals, CI/CD, and secure development concepts.
Exam Topics & Skills Assessed
Skills measured (from the official study guide)
Domain 1: Describe GitHub Security suites, features, and ecosystem
Subdomain 1.1: Understand GitHub Security suites and architecture
Describe GitHub Security suite structure and navigation Contrast Code Security, Secret Protection, and Supply Chain Security Differentiate security feature availability for public repositories vs. enterprise environments Explain features and benefits of the Security Overview
Subdomain 1.2: Apply secure SDLC and security strategies
Explain differences and interplay between Secret Protection and Code Security Describe end-to-end secure SDLC using GitHub Security suites Compare prevention-first approaches vs. gate-based security strategies Explain security campaigns and their role in reducing risk
Subdomain 1.3: Detect, manage, and respond to security alerts
Identify vulnerability and secret detection mechanisms Choose and act on security alerts (alert management, policies, workflows) Explain implications and best practices for ignoring or dismissing alerts Describe developer, security, and admin responsibilities for alerts and remediation
Subdomain 1.4: Manage access, governance, and supply chain security
Explain alert access management, roles, delegated bypass, and enforcement Describe supply chain security concepts and alert information across the SDLC
Domain 2: Configure and use Secret Protection (formerly secret scanning)
Subdomain 2.1: Enable and configure Secret Protection
Enable GitHub Secret Protection at the repository and organization levels Configure Secret Protection settings and feature availability Contrast Secret Protection behavior for public vs. private/enterprise repositories
Subdomain 2.2: Prevent secret exposure
Explain Push Protection and how it prevents secrets at the source Describe validity checks and prioritized alerting for high-confidence secrets
Subdomain 2.3: Manage and respond to Secret Protection alerts
Describe the Secret Protection alert lifecycle (creation, status, dismissal) Respond to secret alerts and apply appropriate remediation actions Explain implications and best practices for dismissing or ignoring alerts
Subdomain 2.4: Control access, policies, and customization
Explain role-based and delegated bypass policies in Secret Protection Configure alert recipients and exclusions Create and manage custom secret patterns
Domain 3: Configure and use supply chain security (formerly Dependabot/Dependency Review)
Subdomain 3.1: Understand and manage dependency and supply chain risks
Comprehensive dependency security (tools, vulnerability databases, SBOMs) Generate and interpret the dependency graph SBOM usage: export options, formats, and supply chain context
Subdomain 3.2: Detect, prioritize, and respond to supply chain alerts
Supply chain alerts and security updates (prioritization, EPSS scoring) Remediating supply chain alerts through campaigns and pull requests Auto-dismiss behavior and security campaign configuration
Subdomain 3.3: Secure dependencies during development
Dependency Review (pre-merge checks, license and compliance validation, configuration) Advanced dependency update rules (grouping, auto-dismiss, update strategies)
Subdomain 3.4: Configure policies, permissions, and integrations
Permissions and role-based alert assignment Workflow management for dependency and supply chain security External notifications, webhooks, and security integrations
Domain 4: Configure and use Code Security (formerly Code Scanning with CodeQL)
Subdomain 4.1: Understand code scanning approaches and tooling
Native and third-party code scanning options Choosing between CodeQL and third-party analysis tools SARIF file ingestion, management, and interoperability
Subdomain 4.2: Set up and configure Code Security
Enable code security using GitHub Actions or external CI systems Configure code scanning workflows and workflow templates Use matrix builds and define appropriate scan frequency
Subdomain 4.3: Analyze, triage, and remediate code scanning results
Review scan results, including dataflow analysis insights Alert lifecycles, autofix capabilities, and remediation workflows Dismissing alerts and managing severity and category classifications
Subdomain 4.4: Optimize and automate Code Security operations
Advanced configuration and customization Troubleshooting scan failures and performance issues
Domain 5: Security operations: best practices, prioritization, and remediation
Subdomain 5.1: Understand vulnerability context and remediation frameworks
CVE, CWE, and GitHub Security Advisory concepts End-to-end remediation workflows across security alerts and advisories
Subdomain 5.2: Prioritize and manage security work at scale
Defining, prioritizing, and enforcing severity and remediation rulesets Campaign-based remediation strategies and bulk alert management Automated alert dismissal and documentation practices
Subdomain 5.3: Customize and optimize security detection
Customizing CodeQL query suites and language-specific analysis Tailoring security detection to organizational risk profiles
Subdomain 5.4: Collaborate across roles and enforce governance
Security roles, delegated exceptions, and alert ownership Collaboration on alerts and security campaigns across teams Cross-suite rulesets, policies, and enforcement mechanisms
Subdomain 5.5: Shift left and strengthen preventive security
Early vulnerability prevention through push protection, dependency scanning, and pre-merge analysis
Domain 6: GitHub Security suites administration
Subdomain 6.1: Roll out and manage security features at scale
Enable GitHub Security Suites at enterprise, organization, and repository levels Understand feature availability and differences across GitHub Enterprise Cloud and GitHub Enterprise Server
Subdomain 6.2: Configure security features and defaults
Enable Code Security (CodeQL), Secret Protection, and Supply Chain Security Define default configurations and inheritance behavior
Subdomain 6.3: Define governance, access, and Code Security workflows
Define enterprise and organization security policies and rulesets Configure enforcement boundaries, bypass permissions, and exceptions Define administrator, security manager, and developer roles Configure permissions for managing and dismissing security alerts Enable and configure default or approved custom CodeQL workflows Understand APIs and automation methods for large-scale security configuration and governance
Subdomain 6.4: Manage CodeQL and security automation
Enable and configure default or approved custom CodeQL workflows Understand available APIs and automation methods for large-scale security configuration and governance
Techniques & products