🔥 3-day streak
GitHub Advanced Security (GH-500)120 / 144
Question 120 of 144

A platform engineering team at a mid-sized company uses Secret Protection across all private repositories. During a review, a security analyst notices that GitHub automatically flagged an exposed cloud provider API token in one repo, but a hardcoded internal database password used by the same application was never detected by secret scanning. The internal password does not match any known provider format. What is the MOST appropriate action to ensure this type of internal credential is detected going forward?

Reviewed for accuracy · Report an issueNext question