Pass the Microsoft GitHub Administrator GH-500 Questions and answers with CertsForce

Viewing page 2 out of 3 pages
Viewing questions 11-20 out of questions
Questions # 11:

Which patterns are secret scanning validity checks available to?

Options:

A.

High entropy strings


B.

Custom patterns


C.

Partner patterns


D.

Push protection patterns


Expert Solution
Questions # 12:

Which of the following information can be found in a repository's Security tab?

Options:

A.

Number of alerts per GHAS feature


B.

Two-factor authentication (2FA) options


C.

Access management


D.

GHAS settings


Expert Solution
Questions # 13:

Which of the following is the best way to prevent developers from adding secrets to the repository?

Options:

A.

Create a CODEOWNERS file


B.

Make the repository public


C.

Configure a security manager


D.

Enable push protection


Expert Solution
Questions # 14:

Which alerts do you see in the repository's Security tab? (Each answer presents part of the solution. Choose three.)

Options:

A.

Repository permissions


B.

Secret scanning alerts


C.

Dependabot alerts


D.

Security status alerts


E.

Code scanning alerts


Expert Solution
Questions # 15:

Which of the following features helps to prioritize secret scanning alerts that present an immediate risk?

Options:

A.

Non-provider patterns


B.

Push protection


C.

Custom pattern dry runs


D.

Secret validation


Expert Solution
Questions # 16:

As a repository owner, you want to receive specific notifications, including security alerts, for an individual repository. Which repository notification setting should you use?

Options:

A.

Ignore


B.

Participating and @mentions


C.

All Activity


D.

Custom


Expert Solution
Questions # 17:

Assuming that notification settings and Dependabot alert recipients have not been customized, which user account setting should you use to get an alert when a vulnerability is detected in one of your repositories?

Options:

A.

Enable all in existing repositories


B.

Enable by default for new public repositories


C.

Enable all for Dependabot alerts


D.

Enable all for Dependency graph


Expert Solution
Questions # 18:

In a private repository, what minimum requirements does GitHub need to generate a dependency graph? (Each answer presents part of the solution. Choose two.)​

Options:

A.

Read-only access to all the repository's files


B.

Dependency graph enabled at the organization level for all new private repositories


C.

Write access to the dependency manifest and lock files for an enterprise


D.

Read-only access to the dependency manifest and lock files for a repository​


Expert Solution
Questions # 19:

What filter or sort settings can be used to prioritize the secret scanning alerts that present the most risk?

Options:

A.

Sort to display the oldest first


B.

Sort to display the newest first


C.

Filter to display active secrets


D.

Select only the custom patterns


Expert Solution
Questions # 20:

A repository's dependency graph includes:

Options:

A.

Dependencies parsed from a repository's manifest and lock files.


B.

Annotated code scanning alerts from your repository's dependencies.


C.

A summary of the dependencies used in your organization's repositories.


D.

Dependencies from all your repositories.


Expert Solution
Viewing page 2 out of 3 pages
Viewing questions 11-20 out of questions