When configuring code scanning with CodeQL, what are your options for specifying additional queries? (Each answer presents part of the solution. Choose two.)
Which of the following benefits do code scanning, secret scanning, and dependency review provide?
When using the advanced CodeQL code scanning setup, what is the name of the workflow file?
Which details do you have to provide to create a custom pattern for secret scanning? (Each answer presents part of the solution. Choose two.)
A dependency has a known vulnerability. What does the warning message include?
Which of the following Watch settings could you use to get Dependabot alert notifications? (Each answer presents part of the solution. Choose two.)
Which of the following tasks can be performed by a security team as a proactive measure to help address secret scanning alerts? (Each answer presents a complete solution. Choose two.)
What role is required to change a repository's code scanning severity threshold that fails a pull request status check?
Which of the following is the most complete method for Dependabot to find vulnerabilities in third-party dependencies?
You are managing code scanning alerts for your repository. You receive an alert highlighting a problem with data flow. What do you click for additional context on the alert?
A secret scanning alert should be closed as "used in tests" when a secret is:
What should you do after receiving an alert about a dependency added in a pull request?
As a repository owner, you want to receive specific notifications, including security alerts, for an individual repository. Which repository notification setting should you use?