GitHub study plan

GH-500 study plan

7 stages6 domains coveredFree practice, no sign-up

A step-by-step GH-500 study plan: the exact order to study in, how long to spend on each stage, and when to start practice questions. Follow it top to bottom.

The real GH-500 is Approximately 75 questions in 90 minutes, pass mark 700 / 1000. For the full domain-by-domain breakdown behind each stage, read the GH-500 study guide.

Your step-by-step plan

  1. Map the blueprint and book a date

    Day 1

    Read the official GitHub exam objectives and the six areas with their weights. Book a provisional date now: a fixed date turns open-ended study into a plan and is the strongest predictor of actually sitting. Note that describing the suites, Secret Protection, supply chain security, and security operations each carry the heaviest weight, so plan the most study across those four.

  2. Build the product and scope maps

    Week 1

    Before drilling any area, build the two maps the whole exam rests on. First the product map: code scanning with CodeQL under Code Security, secret scanning and push protection under Secret Protection, and the dependency graph, Dependabot, and dependency review as supply chain features, with which are free on public repositories. Second the scope map: repository versus organisation versus enterprise, security configurations and their defaults, and what only covers future repositories. Use the recall prompts here: cover the answer, choose from the requirement, then reveal.

  3. Go deep on Secret Protection and supply chain security

    Weeks 1 to 2

    These are heavy and full of trap distinctions. For Secret Protection, lock the lifecycle behaviour (history backfill on enablement, alerts reopening on re-commit) and that remediation means rotating the live credential. For supply chain, fix the Dependabot alerts versus security updates versus version updates split, dependency review with fail-on-severity and licence lists, and the dependency graph and SBOM behaviour. Practise on scenario questions and read the worked explanation on every one, including the ones you got right.

  4. Lock Code Security and the CodeQL model

    Weeks 2 to 3

    Code Security rewards precision. Fix default setup versus advanced setup, how third-party SARIF becomes native alerts via upload-sarif, and the SARIF level versus security-severity distinction. Practise reading a CodeQL data flow path and placing a sanitiser between source and sink, and learn model packs with data extensions for a custom sanitiser. Do the SARIF-ingestion and data-flow calls by hand until the requirement alone decides them.

  5. Cover security operations and remediation at scale

    Weeks 3 to 4

    Drill the CVE versus CWE versus CVSS distinction, GitHub-reviewed versus unreviewed advisories and why only the former alert, CodeQL suite filtering by precision, and the threat-models: local setting. Then practise campaign-based and bulk remediation and how prevention controls reduce future operational load. Tie every choice back to the requirement named and to a prevention-first posture.

  6. Master administration scope and rulesets

    Week 4

    Administration is dependable marks once scope is automatic. Drill enterprise versus organisation versus repository configuration, that a default only governs future repositories so existing ones need bulk attachment, the three ruleset enforcement statuses with evaluate as the dry run, the Always versus Pull request bypass modes, and the security manager role versus organisation owner. Practise the calls until the correct tier and status are reflexive.

  7. Drill weak areas, then sit a timed mock

    Weeks 4 to 5

    Use your per-domain accuracy to attack the two areas dragging you down rather than re-reading what you know, then space the review of each area's recall prompts after a few days and again a week later. Finish with at least one full timed mock under exam conditions to rehearse pacing and the flag-and-return habit, and review every missed question by naming the requirement and scope you misread before you book or sit.

Ready to start stage one?

Free GH-500 questions with worked explanations. No sign-up.

Practise GH-500 free

Frequently asked questions

How long does this GH-500 study plan take?

It is 7 stages, paced by how much time you can give it each week - most candidates work through it in 2 to 6 weeks. Each stage below has a suggested duration; slow down on any stage where the recall checks in the study guide are not landing before moving on.

What order should I study GH-500 in?

Follow the stages in order below. They are sequenced deliberately: foundational material first, then the domains weighted heaviest on the exam, then timed practice, with review passes built in rather than left to the end.

Do I need practice questions as part of this plan?

Yes. Reading alone does not surface what you have not actually learned. This plan builds in graded practice, and the full 292-question bank is free to use as you work through each stage.

Is this plan enough on its own, or do I need the full study guide too?

This page is the plan: what to do and in what order. The study guide adds the domain-by-domain breakdown, easy-to-confuse traps, and worked examples behind each stage - read it alongside this plan, not instead of it.

Examworthy is not affiliated with or endorsed by GitHub. This study plan is original material based on the public exam blueprint. We never reproduce live exam items. GH-500 and related marks belong to their respective owners.