127 practice questions for GitHub Advanced Security certification (GH-500), with full explanations.
Every question comes with the correct answer, the reasoning behind it, and a short note on why each wrong option is wrong. Work through it once with the answers, then again with the questions-only copy under exam conditions.
- 127 questions mapped to the GH-500 exam objectives
- Answers and explanations for every question, including the wrong options
- A questions-only PDF for timed practice runs
- Instant delivery by email the moment you check out
- Free monthly updates for as long as the exam is live
- Pass or your money back
A GH-500 attempt costs US$99. This pack is US$39, paid once.
Try 10 questions free before you buy.
Last updated September 2026 · 127 questions
What makes the GH-500 hard
GH-500 was rebuilt in July 2026 around GitHub’s renamed security suites. The blueprint now says Secret Protection, not secret scanning; Supply Chain Security, not Dependabot; Code Security, not code scanning with CodeQL. Six domains replace the old five, with a new administration domain on rolling the suites out at enterprise, organisation and repository level, and Microsoft’s change log marks the exam as significantly changed.
The weighting is flat, so nothing can be skipped. Secret Protection, supply chain and security operations are 15 to 20% each: push protection, validity checks and custom patterns; the dependency graph, SBOM export and EPSS-scored prioritisation; and CVE, CWE and GitHub Security Advisory concepts with campaign-based remediation.
Code Security expects SARIF ingestion, CodeQL versus third-party tools, matrix scans and autofix. The administration domain adds default configurations and inheritance, enforcement boundaries, security manager roles, and the GHEC versus GHES feature differences.
About the exam
GH-500 (GitHub Advanced Security) is delivered by Microsoft and maintained by GitHub. It covers the GitHub Security suites and secure SDLC, Secret Protection, supply chain security, Code Security with CodeQL, security operations and remediation, and administering the security suites at scale. It is an intermediate-level exam with no prerequisites, and skills are measured as of July 2026.
Exam domains
- Describe GitHub Security suites, features, and ecosystem: 15 to 20%
- Configure and use Secret Protection: 15 to 20%
- Configure and use supply chain security: 15 to 20%
- Configure and use Code Security: 10 to 15%
- Security operations: best practices, prioritization, and remediation: 15 to 20%
- GitHub Security suites administration: 10 to 15%
Passing score 700 out of 1000, US$99 per attempt, online proctored or test centre, certification valid for two years.






Reviews
There are no reviews yet.