🔥 3-day streak
GitHub Advanced Security (GH-500)111 / 144
Question 111 of 144
A security engineer at a fintech company receives a secret scanning alert indicating a valid cloud provider API key was committed to a private repository three weeks ago. The commit history shows the key has been present across multiple branches and was pushed before push protection was enabled. According to GitHub's recommended response workflow, what should the engineer do FIRST to properly respond to this alert?
Reviewed for accuracy · Report an issueNext question