Which of the following formats are used to describe a Dependabot alert? Each answer presents a complete solution. (Choose two.)
Correct Answer: A,C
Dependabot alerts utilize standardized identifiers to describe vulnerabilities: CVE (Common Vulnerabilities and Exposures):A widely recognized identifier for publicly known cybersecurity vulnerabilities. CWE (Common Weakness Enumeration):A category system for software weaknesses and vulnerabilities. These identifiers help developers understand the nature of the vulnerabilities and facilitate the search for more information or remediation strategies. Note: Dependabot alerts utilize standardized identifiers like Common Vulnerabilities and Exposures (CVE) identifiers and GitHub Advisory IDs to describe vulnerabilities within your project's dependencies. These identifiers help link the specific vulnerability to a standardized database entry, providing more context and details about the issue. Publicly disclosed CWEs used by the Dismiss low impact issues for development-scoped dependencies rule Along with the ecosystem:npm and scope:development alert metadata, we use the following GitHub-curated Common Weakness Enumerations (CWEs) to filter out low impact alerts for the Dismiss low impact issues for development-scoped dependencies rule. We regularly improve this list and vulnerability patterns covered by built-in rules. Resource Management Issues CWE-400 Uncontrolled Resource Consumption CWE-770 Allocation of Resources Without Limits or Throttling Etc. Incorrect: [Not A] Dependabot alerts, combined with Vulnerability Exploitability eXchange (VEX), help users understand and manage vulnerabilities in their dependencies. Dependabot provides alerts when vulnerable dependencies are found, and VEX adds context about whether those vulnerabilities are actually exploitable in a specific environment. VEX (Vulnerability Exploitability eXchange): Purpose: VEX provides a standardized way to communicate whether a vulnerability is actually exploitable in a specific context, like a particular product or environment. Functionality: VEX can be used to convey that a vulnerability doesn't pose a risk in a specific scenario, potentially due to specific configurations or mitigations. Example: If a product uses a vulnerable component, but that component is not reachable or has a mitigation in place, VEX can be used to communicate that the vulnerability is not exploitable. [Not D] Dependabot helps users focus on the most important alerts by including EPSS scores that indicate likelihood of exploitation, now generally available [February 2025] Dependabot alerts now feature the Exploit Prediction Scoring System (EPSS) from the global Forum of Incident Response and Security Teams (FIRST), helping you better assess vulnerability risks. EPSS scores predict the likelihood of a vulnerability being exploited, with scores ranging from 0 to 1 (0 to 100%). Higher scores mean higher risk. We also show the EPSS score percentile, indicating how a vulnerability compares to others. For example, a 90.534% EPSS score at the 95th percentile means: 90.534% chance of exploitation in the next 30 days 95% of other vulnerabilities are less likely to be exploited You can use EPSS scores to help prioritize dependency vulnerabilities based on exploit likelihood.
GH-500 Exam Question 47
Assuming that notification settings and Dependabot alert recipients have not been customized, which user account setting should you use to get an alert when a vulnerability is detected in one of your repositories?
Correct Answer: B
To ensure you're notified whenever a vulnerability is detected via Dependabot, you mustenablealerts for Dependabotin your personal notification settings. This applies to both new and existing repositories. It ensures you get timely alerts about security vulnerabilities. [Not C] The dependency graph must be enabled for scanning, but does not send alerts itself.
GH-500 Exam Question 48
Which of the following options would close a Dependabot alert?
Correct Answer: C
To close a Dependabot alert, the primary method is to address the underlying vulnerability. This usually involves merging a pull request that Dependabot creates to update the vulnerable dependency or manually fixing the issue and pushing the updated code. Once the vulnerability is resolved, the alert will be automatically closed. Alternatively, you can manually close alerts in the "Security" tab of your repository. Here's a more detailed breakdown: 1. Addressing the Vulnerability: *-> Merge Dependabot Pull Requests: If Dependabot has identified a vulnerability and created a pull request to fix it, review and merge the pull request. This will automatically update the dependency and close the alert. * Manual Fix: If you prefer to fix the vulnerability yourself, make the necessary code changes to update the dependency. Once the changes are pushed and merged, Dependabot will recognize the fix and close the alert. 2. Manually Closing Alerts (if needed)
GH-500 Exam Question 49
You have a GitHub Enterprise Cloud Organization that contains a private repository named Repo1 and has GitHub Secret Protection enabled. Repo1 contains a workflow that writes an access key ID to config.txt and a secret access key to secrets.txt. Repo1 has secret scanning push protection enabled. You discover that a developer at your company was able to push changes that contain both the access key ID and the secret access key without the push being blocked. What is the cause of the issue?
Correct Answer: D
Secret validation rules: GitHub's secret scanning push protection for AWS credentials checks for a high-confidence pair (the Access Key ID and Secret Access Key) appearing together within the same file or immediate context to prevent false positives. Separation bypasses detection: Because the developer placed the Access Key ID in config.txt and the Secret Access Key in secrets.txt, the push protection pattern matching did not recognize them as a coupled, valid secret pair, allowing the push to succeed. Incorrect: [Not B] The push did NOT include a merge into the default branch: This is incorrect because push protection scans all pushes to any branch within the repository, not just the default branch, to prevent secrets from entering the commit history anywhere. [Not C] The push was performed on a private repository: This is incorrect because GitHub Enterprise Cloud organizations can enable secret scanning and push protection for both public and private repositories alike. Reference: https://rogierdijkman.medium.com/privilege-escalation-via-storage-accounts-bca24373cc2e
GH-500 Exam Question 50
As a developer, you need to configure a code scanning workflow for a repository where GitHub Advanced Security is enabled. What minimum repository permission do you need?
Correct Answer: D
Configuring advanced setup for code scanning with CodeQL You can customize your CodeQL analysis by creating and editing a workflow file. Selecting advanced setup generates a basic workflow file for you to customize using standard workflow syntax and specifying options for the CodeQL action. See Workflows and Customizing your advanced setup for code scanning. Using actions to run code scanning will use minutes. Note: You can configure code scanning for any public repository where you have write access.