🔥 3-day streak
GitHub Advanced Security (GH-500)76 / 144
Question 76 of 144
A developer at your company notices a secret scanning alert flagging an AWS access key that was committed to a repository three weeks ago. The developer confirms the key is real and is still active in the AWS account. Under time pressure, they consider simply dismissing the alert in GitHub as 'used in tests' so the CI dashboard turns green. As the security lead, what is the most important thing you must communicate about the implications of this action?
Reviewed for accuracy · Report an issueNext question