🔥 3-day streak
GitHub Advanced Security (GH-500)47 / 144
Question 47 of 144
Your organization uses an internal service that issues API tokens in the format 'ACME-' followed by exactly 32 hexadecimal characters. These tokens are not detected by GitHub's built-in secret scanning patterns. As a security admin, you want secret scanning to detect these tokens across all repositories, and you want to see which existing tokens would be flagged before the pattern goes live. What should you do?
Reviewed for accuracy · Report an issueNext question