GITHUB · GH-500

GitHub GH-500 Advanced Security Exam Practice Questions

127 questionsPDF by emailUpdated September 2026

US$39

Try 10 questions free

Card, Apple Pay or Google Pay. Your PDF is sent by email as soon as you check out.

Pass or your money backFail the exam after using this pack and we refund it. How the guarantee works
Category:
TRY BEFORE YOU BUY

Three of the 127 questions in this pack

Question 1

A secret scanning alert should be closed as “used in tests” when a secret is:

  1. in a test file.
  2. solely used for tests.
  3. in the readme.md file.
  4. not a secret in the production environment.
Show answer and explanation

Correct answer: B. solely used for tests.

The 'used in tests' closure reason applies specifically when a secret is solely used for testing purposes, meaning it has no actual value in production and poses no real security risk. This classification indicates the alert is a false positive in terms of actual exposure.

Why the other options are wrong

  • A. Being in a test file doesn't guarantee the secret is only used for tests; it could still be a valid secret.
  • C. Secrets in readme.md files should be treated as exposed secrets, not test-only secrets, regardless of documentation context.
  • D. A secret not used in production could still be a real secret used in staging or development environments.

Question 2

What happens when you enable secret scanning on a private repository?

  1. Repository administrators can view Dependabot alerts.
  2. Dependency review, secret scanning, and code scanning are enabled.
  3. Your team is subscribed to security alerts.
  4. GitHub performs a read-only analysis on the repository.
Show answer and explanation

Correct answer: D. GitHub performs a read-only analysis on the repository.

repository. When secret scanning is enabled on a private repository, GitHub performs a read-only analysis of the repository's content to detect secrets. This non-intrusive analysis scans the codebase without modifying it or automatically enabling other features.

Why the other options are wrong

  • A. Enabling secret scanning does not automatically enable Dependabot alerts or grant Dependabot-specific permissions.
  • B. Secret scanning alone does not automatically enable dependency review or code scanning; these are separate features that must be enabled independently.
  • C. Enabling secret scanning does not automatically subscribe the team to security alerts; subscription settings are configured separately.

Question 3

Which of the following statements best describes secret scanning push protection?

  1. Buttons for sensitive actions in the GitHub UI are disabled.
  2. Commits that contain secrets are blocked before code is added to the repository.
  3. Users need to reply to a 2FA challenge before any push events.
  4. Secret scanning alerts must be closed before a branch can be merged into the repository.
Show answer and explanation

Correct answer: B. Commits that contain secrets are blocked before code is added to the repository.

code is added to the repository. Secret scanning push protection is a preventative feature that blocks commits containing detected secrets before they are pushed to the repository. This protects sensitive information from ever reaching the repository by intercepting the push operation at the client side.

Why the other options are wrong

  • A. Push protection blocks commits themselves, not UI buttons; it operates at the git push level, not the GitHub UI level.
  • C. Push protection does not involve 2FA challenges; it uses pattern matching to detect secrets and blocks the push directly.
  • D. Push protection blocks commits before they are added to the repository, not after via merge gate requirements on branches.

See all 10 free questions Get the full pack, US$39

127 practice questions for GitHub Advanced Security certification (GH-500), with full explanations.

Every question comes with the correct answer, the reasoning behind it, and a short note on why each wrong option is wrong. Work through it once with the answers, then again with the questions-only copy under exam conditions.

  • 127 questions mapped to the GH-500 exam objectives
  • Answers and explanations for every question, including the wrong options
  • A questions-only PDF for timed practice runs
  • Instant delivery by email the moment you check out
  • Free monthly updates for as long as the exam is live
  • Pass or your money back

A GH-500 attempt costs US$99. This pack is US$39, paid once.

Try 10 questions free before you buy.

Last updated September 2026 · 127 questions

What makes the GH-500 hard

GH-500 was rebuilt in July 2026 around GitHub’s renamed security suites. The blueprint now says Secret Protection, not secret scanning; Supply Chain Security, not Dependabot; Code Security, not code scanning with CodeQL. Six domains replace the old five, with a new administration domain on rolling the suites out at enterprise, organisation and repository level, and Microsoft’s change log marks the exam as significantly changed.

The weighting is flat, so nothing can be skipped. Secret Protection, supply chain and security operations are 15 to 20% each: push protection, validity checks and custom patterns; the dependency graph, SBOM export and EPSS-scored prioritisation; and CVE, CWE and GitHub Security Advisory concepts with campaign-based remediation.

Code Security expects SARIF ingestion, CodeQL versus third-party tools, matrix scans and autofix. The administration domain adds default configurations and inheritance, enforcement boundaries, security manager roles, and the GHEC versus GHES feature differences.

About the exam

GH-500 (GitHub Advanced Security) is delivered by Microsoft and maintained by GitHub. It covers the GitHub Security suites and secure SDLC, Secret Protection, supply chain security, Code Security with CodeQL, security operations and remediation, and administering the security suites at scale. It is an intermediate-level exam with no prerequisites, and skills are measured as of July 2026.

Exam domains

  • Describe GitHub Security suites, features, and ecosystem: 15 to 20%
  • Configure and use Secret Protection: 15 to 20%
  • Configure and use supply chain security: 15 to 20%
  • Configure and use Code Security: 10 to 15%
  • Security operations: best practices, prioritization, and remediation: 15 to 20%
  • GitHub Security suites administration: 10 to 15%

Passing score 700 out of 1000, US$99 per attempt, online proctored or test centre, certification valid for two years.

Reviews

There are no reviews yet.

Only logged in customers who have purchased this product may leave a review.

Questions before you buy

What do I get when I buy the GitHub GH-500 Advanced Security pack?

127 practice questions as a PDF, each with the correct answer, a full explanation and a note on why the other options are wrong, plus a separate questions-only PDF for timed practice.

How quickly do I receive it?

Your PDF is prepared and sent to your email address after checkout, and you get a confirmation as soon as it is on its way.

Is there a free sample?

Yes. Ten questions from this pack, with answers and explanations, are free on this page and as a PDF, so you can judge the quality before you pay.

Are updates included?

Yes. The pack is updated every month for as long as the exam is live, and updates are free for everyone who has bought it.

What if I fail the exam?

We refund the pack. Sit the exam 7 to 30 days after buying, then send your official score report within 7 days of the exam date, as set out in the refund policy.

Can I share it with colleagues?

Each purchase is licensed to one person. For a team, school or training organisation, email support@certstash.com for a licence that fits.