🔥 3-day streak
GitHub Advanced Security (GH-500)104 / 144
Question 104 of 144
A platform security lead wants to reduce the number of secret-scanning alerts that reach the triage queue by stopping credentials from ever entering the repository. Developers report that most leaks happen when they commit and push local config files containing API keys. Which combination of measures best embodies a 'shift-left' preventive approach for this specific problem, rather than a detect-and-remediate approach?
Reviewed for accuracy · Report an issueNext question