CertGrid
GitHub Study Guide

GitHub Advanced Security Study Guide

GitHub Advanced Security (GH-500) validates that you can secure code across the software supply chain using GitHub's security features: secret scanning and push protection, supply chain security with Dependabot and dependency review, code scanning with CodeQL, and security administration across GitHub Enterprise Cloud and Server. It is aimed at security engineers, DevOps practitioners, and administrators responsible for rolling out and operating these capabilities. GitHub now offers them as two standalone products, GitHub Secret Protection and GitHub Code Security, and the exam covers feature functionality and availability, alert triage and remediation, custom CodeQL queries, security operations, and enterprise licensing and configuration.

Objective-mapped study guide, aligned to current exam objectives · Reviewed Jul 2026 · Independent practice platform.

Real exam: ~75 qs · 100 min

Domain 1: GitHub Security Suites, Features, and Ecosystem

Key concepts you must know · 78 practice questions

Domain 2: Secret Protection

Key concepts you must know · 128 practice questions

Domain 3: Supply Chain Security

Key concepts you must know · 118 practice questions

Domain 4: Code Security

Key concepts you must know · 218 practice questions

Domain 5: Security Operations and Remediation

Key concepts you must know · 121 practice questions

Domain 6: GitHub Security Suites Administration

Key concepts you must know · 90 practice questions

GitHub Advanced Security exam tips

Study guide FAQ

How many questions are on the GH-500 exam and what is the passing score?

The GitHub Advanced Security exam draws from a large pool and is delivered in 100 minutes with a scaled passing score of 700. It covers all of GitHub's security features from secret scanning through enterprise administration.

Do I need a GHAS license to use Dependabot?

No. Dependabot alerts are a free core feature that works on private repositories without a GHAS license. A GHAS license is required for secret scanning, push protection, and CodeQL code scanning on private and internal repositories.

What is the difference between default setup and advanced setup for code scanning?

Default setup enables CodeQL with minimal configuration and automatic language detection, while advanced setup uses an editable workflow file. Choose advanced setup when you need custom build commands or want to combine CodeQL with an external SARIF-producing tool.

How does GHAS billing count usage?

GHAS bills by active committers, a unique user counted if they pushed to a GHAS-enabled repository within the last 90 days. External collaborators count too, and removing a user's access does not immediately clear their count until the 90-day window elapses.

Related GitHub resources

What CertGrid is (and is not)

CertGrid is an independent IT certification practice platform for Azure, AWS, Google, Cisco, Security, Linux, Kubernetes, Terraform, and other certification tracks. It provides objective-mapped practice questions, readiness scoring, weak-domain drills, and explanations to help learners understand what to study next.

Independent & original. CertGrid is an independent practice platform and is not affiliated with or endorsed by GitHub. Questions are original practice items designed to mirror certification concepts and exam style. CertGrid does not provide official exam questions or braindumps.