Limited-Time Offer: Enjoy 50% Savings! - Ends In 0d 00h 00m 00s Coupon code: 50OFF
Free Exam Questions

GH-500 Exam Questions & Answers

GitHub Advanced Security Exam  •  Microsoft

75 Questions 100 min Updated Sep 2026 99% Pass Rate
Get Full Access

100% money-back guarantee

Sample GH-500 Questions

Practice with real exam-style questions, each with the verified correct answer and explanation.

Q1 MultipleChoice

-- [Configure and Use Dependency Management]

Which of the following options would close a Dependabot alert?

Correct Answer: A
Explanation:

A Dependabot alert is only marked as resolved when the related vulnerability is no longer present in your code --- specifically after you merge a pull request that updates the vulnerable dependency.

Simply viewing alerts or graphs does not affect their status. Ignoring the alert by leaving the repo unchanged keeps the vulnerability active and unresolved.

Q2 MultipleChoice

-- [Describe the GHAS Security Features and Functionality]

Which of the following information can be found in a repository's Security tab?

Correct Answer: A
Explanation:

The Security tab in a GitHub repository provides a central location for viewing security-related information, especially when GitHub Advanced Security is enabled. The following can be accessed:

Number of alerts related to:

Code scanning

Secret scanning

Dependency (Dependabot) alerts

Summary and visibility into open, closed, and dismissed security issues.

It does not show 2FA options, access control settings, or configuration panels for GHAS itself. Those belong to account or organization-level settings.

Q3 MultipleChoice

-- [Use Code Scanning with CodeQL]

As a developer with write access, you navigate to a code scanning alert in your repository. When will GitHub close this alert?

Correct Answer: D
Explanation:

GitHub automatically closes a code scanning alert when the vulnerable code is fixed in the same branch where the alert was generated, usually via a commit inside a pull request. Simply clicking or triaging an alert does not resolve it. The alert is re-evaluated after each push to the branch, and if the issue no longer exists, it is marked as resolved.

Q4 MultipleChoice

-- [Configure and Use Dependency Management]

You are a maintainer of a repository and Dependabot notifies you of a vulnerability. Where could the vulnerability have been disclosed? (Each answer presents part of the solution. Choose two.)

Correct Answer: A, C
Explanation:

Comprehensive and Detailed Explanation:

Dependabot alerts are generated based on data from various sources:

National Vulnerability Database (NVD): A comprehensive repository of known vulnerabilities, which GitHub integrates into its advisory database.

GitHub Docs

Security Advisories Reported on GitHub: GitHub allows maintainers and security researchers to report and discuss vulnerabilities, which are then included in the advisory database.

The dependency graph and manifest/lock files are tools used by GitHub to determine which dependencies are present in a repository but are not sources of vulnerability disclosures themselves.

Q5 MultipleChoice

-- [Configure and Use Secret Scanning]

Which patterns are secret scanning validity checks available to?

Correct Answer: C
Explanation:

Validity checks --- where GitHub verifies if a secret is still active --- are available for partner patterns only. These are secrets issued by GitHub's trusted partners (like AWS, Slack, etc.) and have APIs for GitHub to validate token activity status.

Custom patterns and high entropy patterns do not support automated validity checks.

Get access to all 75 verified questions with detailed answers.

Unlock All GH-500 Questions

Frequently Asked Questions

The GH-500 is Microsoft's GitHub Advanced Security Exam that validates expertise in implementing and managing security features within GitHub. This certification demonstrates proficiency in securing code, managing vulnerabilities, and implementing advanced security practices in development workflows.

The exam covers GitHub security features including secret scanning, dependency management, code scanning, security policies, and security advisories. It also includes topics on implementing security in CI/CD pipelines, managing access controls, and responding to security vulnerabilities.

The GH-500 exam is typically 90 minutes long with approximately 40-60 questions. You need to achieve a minimum score of 70% to pass the certification exam.

Microsoft recommends having hands-on experience with GitHub for at least 6-12 months and practical knowledge of security concepts and tools. Familiarity with DevOps practices, CI/CD pipelines, and general application security principles is also beneficial.

You can register for the GH-500 exam through Microsoft Learn or Pearson Vue's testing centers. The exam can be taken either at a local testing center or remotely through an online proctored option.
Exam Details
  • Exam CodeGH-500
  • VendorMicrosoft
  • Total Questions75
  • Duration100 min
  • LanguageEnglish
  • Last UpdatedSep 2, 2026
4.9/5

Pass GH-500 First Time

Get all 75 exam questions with verified answers and 90-day free updates.

Buy Now & Pass
  • PDF + Practice Test Bundle
  • 90-Day Free Updates
  • 100% Money-Back Guarantee
  • Instant Download
  • 24/7 Customer Support
99% Pass Rate Trusted by 50,000+ IT professionals