Examworthyexamworthy.com

GitHub Advanced Security (GH-500) cheat sheet

GitHub

Exam version 2026Reviewed 2026-06-11

Free to share. Examworthy is not affiliated with or endorsed by GitHub; GH-500 and related marks belong to their respective owners.

At a glance

Approximately 75
Questions
90 min
Time allowed
700 / 1000
Pass mark
$99
Cost (USD)

Format: Multiple choice and multiple response, online proctored

Domain weight map

Heaviest first - spend your time here
Describe GitHub Security suites, features, and ecosystem18% · 53 Q
Configure and use Secret Protection18% · 52 Q
Configure and use supply chain security18% · 50 Q
Security operations: best practices, prioritization, and remediation18% · 55 Q
Configure and use Code Security14% · 42 Q
GitHub Security suites administration14% · 40 Q

How this exam thinks

GH-500 is a configure-the-right-control exam: nearly every question is a scenario where the answer is the documented GitHub Advanced Security feature, enabled at the correct repository, organisation, or enterprise scope, that prevents the problem early rather than remediating it late.

Spot the trap

Tempting wrong answers, and why they fail

Common misconception

That Advanced Security scanning always needs a paid licence. On public repositories code scanning and secret scanning run free, same as Dependabot.

Describe GitHub Security suites, features, and ecosystem

Common misconception

That secret scanning on a public repository needs a paid licence. It runs free automatically for public repos; a paid Secret Protection licence only covers private and internal ones.

Configure and use Secret Protection

Common misconception

That Dependabot alerts come from CodeQL scanning your code for vulnerable calls. Alerts instead come from matching dependency versions against advisory data.

Configure and use supply chain security

Common misconception

That a CVE groups every vulnerability sharing a root cause across products. A CVE names one specific disclosed flaw; CWE is the weakness category.

Security operations: best practices, prioritization, and remediation

Common misconception

That enabling code scanning means CodeQL analyses every language in the repository. CodeQL only covers its supported languages; others need a SARIF-integrated tool.

Configure and use Code Security

Common misconception

That assigning the security manager role makes organisations inherit a standard set of enabled security features. The role only grants visibility and management access, not distribution.

GitHub Security suites administration

Common misconception

That code scanning and secret scanning are cloud-only features. GitHub Enterprise Server supports both, gated behind a GitHub Advanced Security licence rather than being unavailable.

Describe GitHub Security suites, features, and ecosystem

Common misconception

That push protection on a public repository needs a paid Secret Protection licence before it will block anything.

Configure and use Secret Protection

Key terms

GitHub Advanced SecurityCode SecuritySecret ProtectionSupply Chain SecuritySecurity Overviewpublic repositoriesGitHub Enterprise CloudGitHub Enterprise Serverfeature availabilitysecure SDLCprevention-firstgate-based securitysecurity campaignsshift leftsecurity alertsalert management

Exam-day rules

  • Read the scenario for its requirement first. The security need named in the question, paired with the scope it concerns, is what picks the answer, so find both before you judge the options.
  • Prefer the documented, built-in mechanism. When an option describes a supported GitHub feature and another describes a hand-rolled workaround such as re-pushing files or parsing artifacts, the supported feature is almost always the answer.
  • Choose prevention over cleanup. Push protection at push time, dependency review before merge, and a CodeQL pull request scan beat after-the-fact remediation when the scenario allows catching the problem early.
  • Match the enablement scope exactly. Decide whether the action belongs at repository, organisation, or enterprise level, and remember a default security configuration only covers repositories created after it is set, so existing ones need bulk attachment.
  • Map every feature to its product. Code scanning with CodeQL is Code Security, secret scanning and push protection are Secret Protection, and dependency review and Dependabot are supply chain features; licensing questions hinge on this split.

Revision schedule

  1. Day 1
    Map the blueprint and book a date
  2. Week 1
    Build the product and scope maps
  3. Weeks 1 to 2
    Go deep on Secret Protection and supply chain security
  4. Weeks 2 to 3
    Lock Code Security and the CodeQL model
  5. Weeks 3 to 4
    Cover security operations and remediation at scale

Practise GH-500 free

Every question explains why the right answer is right and why each wrong one is rationale. No sign-up.

292 audited flashcards in this deck.

Practise GH-500 free
Examworthy - GitHub Advanced Security (GH-500) cheat sheet. Free to share.examworthy.com