Pass the Microsoft GitHub Administrator GH-500 Questions and answers with CertsForce

Viewing page 2 out of 3 pages
Viewing questions 11-20 out of questions
Questions # 11:

The autobuild step in the CodeQL workflow has failed. What should you do?

Options:

A.

Remove specific build steps.


B.

Compile the source code.


C.

Remove the autobuild step from your code scanning workflow and add specific build steps.


D.

Use CodeQL, which implicitly detects the supported languages in your code base.


Expert Solution
Questions # 12:

How would you build your code within the CodeQL analysis workflow? (Each answer presents a complete solution. Choose two.)​

Options:

A.

Upload compiled binaries.


B.

Use CodeQL's init action.


C.

Ignore paths.


D.

Implement custom build steps.


E.

Use jobs.analyze.runs-on.


F.

Use CodeQL's autobuild action.


Expert Solution
Questions # 13:

Which of the following formats are used to describe a Dependabot alert? (Each answer presents a complete solution. Choose two.)​

Options:

A.

Common Weakness Enumeration (CWE)


B.

Exploit Prediction Scoring System (EPSS)


C.

Common Vulnerabilities and Exposures (CVE)


D.

Vulnerability Exploitability exchange (VEX)​


Expert Solution
Questions # 14:

Which of the following features helps to prioritize secret scanning alerts that present an immediate risk?

Options:

A.

Non-provider patterns


B.

Push protection


C.

Custom pattern dry runs


D.

Secret validation


Expert Solution
Questions # 15:

As a contributor, you discovered a vulnerability in a repository. Where should you look for the instructions on how to report the vulnerability?

Options:

A.

support.md


B.

readme.md


C.

contributing.md


D.

security.md


Expert Solution
Questions # 16:

Where can you view code scanning results from CodeQL analysis?

Options:

A.

The repository's code scanning alerts


B.

A CodeQL database


C.

A CodeQL query pack


D.

At Security advisories


Expert Solution
Questions # 17:

Which of the following Watch settings could you use to get Dependabot alert notifications? (Each answer presents part of the solution. Choose two.)

Options:

A.

The Custom setting


B.

The Participating and @mentions setting


C.

The All Activity setting


D.

The Ignore setting


Expert Solution
Questions # 18:

You are managing code scanning alerts for your repository. You receive an alert highlighting a problem with data flow. What do you click for additional context on the alert?​

Options:

A.

Show paths


B.

Security


C.

Code scanning alerts​


Expert Solution
Questions # 19:

Why should you dismiss a code scanning alert?

Options:

A.

If you fix the code that triggered the alert


B.

To prevent developers from introducing new problems


C.

If it includes an error in code that is used only for testing


D.

If there is a production error in your code


Expert Solution
Questions # 20:

Assuming security and analysis features are not configured at the repository, organization, or enterprise level, secret scanning is enabled on:

Options:

A.

Public repositories


B.

All new repositories within your organization


C.

User-owned private repositories


D.

Private repositories


Expert Solution
Viewing page 2 out of 3 pages
Viewing questions 11-20 out of questions