GitHub study plan
GH-500 study plan
A step-by-step GH-500 study plan: the exact order to study in, how long to spend on each stage, and when to start practice questions. Follow it top to bottom.
The real GH-500 is Approximately 75 questions in 90 minutes, pass mark 700 / 1000. For the full domain-by-domain breakdown behind each stage, read the GH-500 study guide.
Your step-by-step plan
Map the blueprint and book a date
Day 1Read the official GitHub exam objectives and the six areas with their weights. Book a provisional date now: a fixed date turns open-ended study into a plan and is the strongest predictor of actually sitting. Note that describing the suites, Secret Protection, supply chain security, and security operations each carry the heaviest weight, so plan the most study across those four.
Build the product and scope maps
Week 1Before drilling any area, build the two maps the whole exam rests on. First the product map: code scanning with CodeQL under Code Security, secret scanning and push protection under Secret Protection, and the dependency graph, Dependabot, and dependency review as supply chain features, with which are free on public repositories. Second the scope map: repository versus organisation versus enterprise, security configurations and their defaults, and what only covers future repositories. Use the recall prompts here: cover the answer, choose from the requirement, then reveal.
Go deep on Secret Protection and supply chain security
Weeks 1 to 2These are heavy and full of trap distinctions. For Secret Protection, lock the lifecycle behaviour (history backfill on enablement, alerts reopening on re-commit) and that remediation means rotating the live credential. For supply chain, fix the Dependabot alerts versus security updates versus version updates split, dependency review with fail-on-severity and licence lists, and the dependency graph and SBOM behaviour. Practise on scenario questions and read the worked explanation on every one, including the ones you got right.
Lock Code Security and the CodeQL model
Weeks 2 to 3Code Security rewards precision. Fix default setup versus advanced setup, how third-party SARIF becomes native alerts via upload-sarif, and the SARIF level versus security-severity distinction. Practise reading a CodeQL data flow path and placing a sanitiser between source and sink, and learn model packs with data extensions for a custom sanitiser. Do the SARIF-ingestion and data-flow calls by hand until the requirement alone decides them.
Cover security operations and remediation at scale
Weeks 3 to 4Drill the CVE versus CWE versus CVSS distinction, GitHub-reviewed versus unreviewed advisories and why only the former alert, CodeQL suite filtering by precision, and the threat-models: local setting. Then practise campaign-based and bulk remediation and how prevention controls reduce future operational load. Tie every choice back to the requirement named and to a prevention-first posture.
Master administration scope and rulesets
Week 4Administration is dependable marks once scope is automatic. Drill enterprise versus organisation versus repository configuration, that a default only governs future repositories so existing ones need bulk attachment, the three ruleset enforcement statuses with evaluate as the dry run, the Always versus Pull request bypass modes, and the security manager role versus organisation owner. Practise the calls until the correct tier and status are reflexive.
Drill weak areas, then sit a timed mock
Weeks 4 to 5Use your per-domain accuracy to attack the two areas dragging you down rather than re-reading what you know, then space the review of each area's recall prompts after a few days and again a week later. Finish with at least one full timed mock under exam conditions to rehearse pacing and the flag-and-return habit, and review every missed question by naming the requirement and scope you misread before you book or sit.
Ready to start stage one?
Free GH-500 questions with worked explanations. No sign-up.
Frequently asked questions
How long does this GH-500 study plan take?
It is 7 stages, paced by how much time you can give it each week - most candidates work through it in 2 to 6 weeks. Each stage below has a suggested duration; slow down on any stage where the recall checks in the study guide are not landing before moving on.
What order should I study GH-500 in?
Follow the stages in order below. They are sequenced deliberately: foundational material first, then the domains weighted heaviest on the exam, then timed practice, with review passes built in rather than left to the end.
Do I need practice questions as part of this plan?
Yes. Reading alone does not surface what you have not actually learned. This plan builds in graded practice, and the full 292-question bank is free to use as you work through each stage.
Is this plan enough on its own, or do I need the full study guide too?
This page is the plan: what to do and in what order. The study guide adds the domain-by-domain breakdown, easy-to-confuse traps, and worked examples behind each stage - read it alongside this plan, not instead of it.
Examworthy is not affiliated with or endorsed by GitHub. This study plan is original material based on the public exam blueprint. We never reproduce live exam items. GH-500 and related marks belong to their respective owners.