GitHub Advanced Security (GH-500)
GH-500 validates the ability to secure the software supply chain with GitHub Advanced Security: configuring and triaging secret scanning, code scanning with CodeQL, Dependabot alerts and updates, dependency review, and rolling out security features across an organization.
Ready to sit the mock exam?
The timer starts as soon as you begin. You can flag questions, move freely between them, and review everything before submitting. No sign-in required — sign in afterwards to save the result to your history.
Start GH-500 examSkills measured
Describe GitHub Advanced Security Features
15%The GHAS feature set, licensing, security overview, and security policies.
Configure and Use Secret Scanning
20%Push protection, custom patterns, validity checks, alert triage, and remediation.
Configure and Use Code Scanning with CodeQL
30%Default and advanced setup, CodeQL queries and packs, SARIF, and alert management.
Configure and Use Dependabot and Dependency Review
25%Dependency graph, Dependabot alerts, security and version updates, and dependency review.
Roll Out and Govern GHAS
10%Enabling features at organization scale, permissions, and security campaigns.