🔥 3-day streak
GitHub Advanced Security (GH-500)12 / 144
Question 12 of 144
A security engineer at a fintech company is building a remediation runbook. She needs to document the correct end-to-end handling for two different alert types. For a Dependabot alert flagging a vulnerable transitive dependency (with a fix version available), the runbook must specify the primary remediation action that GitHub can automate. For a CodeQL alert flagging a SQL injection in first-party code, the runbook must specify who owns the fix. Which pairing correctly reflects how each remediation workflow operates?
Reviewed for accuracy · Report an issueNext question