🔥 3-day streak
GitHub Advanced Security (GH-500)116 / 144
Question 116 of 144

A security analyst is triaging Secret Scanning alerts in a private repository with GitHub Secret Protection enabled. One alert flags a token that a developer confirms is a fake, non-functional value hardcoded intentionally as a fixture in the automated test suite. The analyst wants to close the alert while preserving accurate context for future audits and reporting. Which action should the analyst take?

Reviewed for accuracy · Report an issueNext question