🔥 3-day streak
GitHub Advanced Security (GH-500)21 / 144
Question 21 of 144
A security architect at a fintech company wants CodeQL analysis to reflect the organization's elevated risk tolerance for injection and cryptographic weaknesses, while suppressing noisy maintainability-related alerts that developers routinely ignore. The team already runs default setup across 200 repositories but finds the standard query set produces too many low-value results and misses some deeper security patterns. Which approach best tailors detection to the organization's risk profile without abandoning centralized management?
Reviewed for accuracy · Report an issueNext question