最新的GitHub Advanced Security GHAS - GitHub-Advanced-Security免費考試真題

問題1
In a private repository, what minimum requirements does GitHub need to generate a dependencygraph? (Each answer presents part of the solution. Choose two.)

正確答案: A,D
說明:(僅 VCESoft 成員可見)
問題2
Assuming that notification and alert recipients are not customized, what does GitHub do when it identifies a vulnerable dependency in a repository where Dependabot alerts are enabled? (Each answer presents part of the solution. Choose two.)

正確答案: A,B
說明:(僅 VCESoft 成員可見)
問題3
When does Dependabot alert you of a vulnerability in your software development process?

正確答案: D
說明:(僅 VCESoft 成員可見)
問題4
What does code scanning do?

正確答案: A
說明:(僅 VCESoft 成員可見)
問題5
In the pull request, how can developers avoid adding new dependencies with known vulnerabilities?

正確答案: A
說明:(僅 VCESoft 成員可見)
問題6
What are Dependabot security updates?

正確答案: C
說明:(僅 VCESoft 成員可見)
問題7
Which CodeQL query suite provides queries of lower severity than the default query suite?

正確答案: A
說明:(僅 VCESoft 成員可見)
問題8
The autobuild step in the CodeQL workflow has failed. What should you do?

正確答案: D
說明:(僅 VCESoft 成員可見)