🔥 3-day streak
GitHub Advanced Security (GH-500)105 / 144
Question 105 of 144
A security engineer at your company discovers that a valid AWS access key was committed months ago and triggered a secret scanning alert. They immediately revoke the key in AWS, rotate credentials, and mark the alert as 'Revoked' in GitHub. Two weeks later, an automated audit shows the same secret string still exists in the repository's Git history on the default branch. What is the correct understanding of the alert's state and the appropriate next action?
Reviewed for accuracy · Report an issueNext question