🔥 3-day streak
GitHub Advanced Security (GH-500)16 / 144
Question 16 of 144
A security team runs a remediation campaign and wants accurate metrics on how many code scanning alerts were genuinely resolved through code changes versus those that were triaged away without a fix. During the campaign, engineers merge PRs that remove the vulnerable code paths, and reviewers also dismiss several alerts they judge to be false positives. When the security lead reviews the code scanning results after the next default-branch scan, how will these two categories of alerts be distinguished in the alert list?
Reviewed for accuracy · Report an issueNext question