GitHub Security suites administration
Drill 20 practice questions focused entirely on GitHub Security suites administration for the GitHub GH-500 exam. Tap an answer for instant feedback and a full explanation — no sign-up, always free.
A platform engineering team at a financial services company is enabling CodeQL default setup across 400 repositories in GitHub Enterprise Cloud. Compliance requires that all CodeQL analysis run on the company's own infrastructure inside a locked-down network segment, and that no analysis workloads execute on GitHub-hosted runners. An enterprise owner asks how to ensure the org-wide CodeQL rollout meets this requirement while still using the automatically managed default setup where possible. What should they do?
A platform engineering team runs GitHub Enterprise Server 3.11 on-premises and is planning to enable code scanning with the default CodeQL setup across all repositories in an organization. During planning, a security manager notes that on GitHub Enterprise Cloud the same default setup 'just works' after clicking enable, but on their Server instance the team must complete an additional infrastructure step before default setup will function. Which prerequisite is unique to enabling CodeQL default setup on GitHub Enterprise Server (as opposed to Enterprise Cloud)?
An enterprise owner has enabled an allowlist of approved GitHub Actions. A security engineer wants organizations to use a shared, centrally maintained custom CodeQL workflow (rather than default setup) so that all repositories analyze code with the organization's mandated query pack. The custom workflow lives in a reusable-workflow repository and is called via a `uses:` reference. Developers report that when they add the reusable workflow reference to their repos, the CodeQL scan job never runs and Actions reports the workflow is not permitted. What is the MOST likely cause and correct remediation?
You are the enterprise administrator for a GitHub Enterprise Cloud organization. Your security team wants developers to be able to run CodeQL default setup, but they also want to permit only a specific, vetted set of third-party GitHub Actions in workflows across all organizations — including a custom CodeQL Action fork the team maintains. Any other Actions should be blocked from running. What is the correct way to enforce this at scale while still allowing the approved custom CodeQL workflow?
At Meridian Corp, an enterprise owner has created a security configuration at the enterprise level and applied it to all organizations. Priya is assigned the security manager role in the 'Payments' organization. She needs to create an additional organization-level security configuration that enables Dependabot version updates for repositories that handle PCI data, and apply it to those repos. However, when she attempts this, she finds she can create the org-level configuration but a subset of settings is locked and cannot be overridden. What best explains this behavior and what she can do?
You are the enterprise administrator for a GitHub Enterprise Cloud instance with 40 organizations and over 5,000 repositories. Leadership wants Code Security (CodeQL default setup) and Secret Protection enabled consistently, with the ability to report on which repositories have applied the settings. You need a repeatable, auditable method that does not require org owners to configure each repository manually. Which approach best meets these requirements?
You are an enterprise owner for a GitHub Enterprise Cloud account. You created an enterprise-level security configuration that enables Dependabot alerts, secret scanning, and push protection, and you applied it to all organizations with the enforcement set so organizations cannot override it. One organization owner reports they need to disable push protection for a small set of legacy repositories that generate excessive false-positive blocks during migration. What is the correct way to accommodate this while keeping enterprise governance intact?
As an enterprise owner on GitHub Enterprise Cloud, you have applied a security configuration to all organizations that enables secret scanning and push protection. Several organization owners have been disabling push protection in their repositories to avoid workflow friction. You need a way to guarantee that these two features remain enabled and that organization owners cannot turn them off, while still allowing them to enable additional features on their own. What should you do?
At GlobalPay, a compliance analyst needs read-only visibility into Dependabot and code scanning alerts across all repositories in the 'payments' organization so they can produce audit reports. The analyst must NOT be able to dismiss alerts, change repository code, or modify security configurations. As the organization owner, what is the most appropriate way to grant this access?
You are the security manager for an organization on GitHub Enterprise Cloud. Leadership wants to guarantee that no pull request targeting the default branch of any repository in the org can be merged unless a CodeQL analysis has completed successfully. You want a single, org-wide control that enforces this consistently across all current and future repositories without editing each repository's branch protection settings individually. Which approach best meets this requirement?
As an organization owner for a GitHub Enterprise Cloud org, you create a custom security configuration that enables Dependabot alerts, secret scanning, and CodeQL default setup. You want every newly created repository in the organization to automatically receive these settings without an admin manually applying them, while leaving existing repositories untouched for now. Within the security configurations interface, what action achieves this?
You are an enterprise owner at a company running GitHub Enterprise Cloud. A newly hired platform engineer needs to create and apply organization-level security configurations (bundling Code Security, Secret Protection, and Dependabot defaults) across all repositories in the 'payments' organization. You want to grant this person the minimum role needed to manage these configurations within that single organization, without giving them the ability to change enterprise-wide policies. Which role assignment satisfies this requirement?
You are an enterprise owner rolling out a GitHub-recommended security configuration across a large organization. You apply the configuration and set it as the default. During review, a security manager notices that many pre-existing repositories still show no security features enabled, while brand-new repositories created afterward automatically receive the configuration. What is the most likely reason the existing repositories were not covered?
You are an enterprise owner planning to standardize security settings across a GitHub Enterprise Cloud organization. You create a security configuration named 'Baseline-Prod' that enables Dependabot alerts, CodeQL default setup, and secret scanning with push protection. You want a single team of platform engineers (not enterprise owners) to be able to attach this configuration to repositories across multiple organizations without granting them full enterprise administration. Which approach correctly delegates this capability while respecting GitHub's permission model?
As an enterprise security administrator, you create a security configuration in an organization that enables Code Security and Secret Protection, and you set the configuration's policy to 'Enforce'. A repository administrator later tries to individually disable secret scanning on a repository the configuration is applied to. What is the outcome, and why?
You are a platform engineer for a company on GitHub Enterprise Cloud. The enterprise owner has applied an enterprise-level security configuration that enables secret scanning push protection and sets it as the default for all new and existing repositories across every organization. Separately, an organization owner in one of the child organizations creates and applies their own organization-level security configuration that leaves push protection disabled, intending to roll it out gradually. A developer reports that push protection is still blocking commits in a repository within that organization. Assuming the enterprise configuration was applied with enforcement, why is push protection still active despite the organization's configuration?
You are the enterprise security admin for a company with 480 organizations and roughly 12,000 repositories on GitHub Enterprise Cloud. Leadership wants Code Security, Secret Protection, and Supply Chain Security enabled consistently, with the ability to programmatically audit which repositories have each feature turned on and to re-apply the standard baseline whenever drift is detected. Which approach best satisfies the requirement for repeatable, large-scale governance?
An enterprise security team applied an organization-level security configuration to all repositories to enable Code Security and Secret Protection. One repository, 'legacy-payments', experiences repeated CodeQL scan failures that block its release pipeline, and the team needs to stop the organization configuration from managing this single repository while leaving all other repositories governed by it. What is the correct action to take from the organization's Code security settings?
You manage a GitHub Enterprise Cloud organization with 200 repositories. Your CISO wants a dedicated group of five security engineers to be able to view all security alerts across every repository and manage security configurations for the organization, but they should NOT receive owner-level administrative control (such as deleting repositories or managing billing). What is the correct way to grant these permissions at scale?
An organization has assigned the built-in Security Manager role to its AppSec team. A separate group of application developers has Write access to several repositories in the org. During an incident review, the CISO asks which group is able to dismiss Dependabot and code scanning alerts across ALL repositories in the organization without being granted per-repository access. Which statement correctly describes the capabilities of these roles?
More GH-500 practice
Keep going with the other GitHub Advanced Security (GH-500) domains, or take a full timed mock exam.
← Back to GH-500 overview