GitHub Advanced Security: prevention and remediation
Seven lessons, 40 questions, and seven cases on credential protection, dependencies, CodeQL, remediation, and security governance.
Objectives and progression
Initial course with seven lessons and 47 original decisions, including seven fictional APS and technical-management cases. Internal assessment of 28 decisions in 60 minutes. Covers six current domains at introductory depth; CodeQL queries, triage rules, enterprise integrations, and executable labs need deeper study. GH-500: July 2026 objectives in the guide updated 2026-05-14. The official page states 100 minutes; passing starts at 700 on a 1000-point scale, without equivalence to 70%. Question count unconfirmed. The credential has two-year validity; consult current renewal and transition policy.
Audience: Development, platform, APS, and technical managers responsible for application security and operations.
Prerequisites: Git, pull requests, CI/CD, and basic dependencies, credentials, and vulnerability management.
375 estimated study minutes
- Choose complementary controls and define the population represented by evidence.
- Distinguish detection, validity, containment, and secret-alert closure.
- Assess actual dependencies and apply updates with compatibility evidence.
- Choose suitable analysis and interpret results without confusing execution with coverage.
- Turn alerts into remediation decisions with context and accountability.
- Confirm coverage and track the fix through to affected runtime.
- Confirm central-policy outcomes on each in-scope repository.
Modules
- Products, scope, and prevention
- Credentials, response, and exceptions
- Dependencies, inventory, and merge prevention
- CodeQL, coverage, and SARIF results
- Priorities, campaigns, and exceptions
- Validation and production handover
- Administration and effective policy application
Continue learning
References and version
GH-500 skills measured July2026;study guide updated2026-05-14
- GitHub Advanced Security certification · 2026-09-30
- GH-500 July 2026 objectives · 2026-09-30
- Scaled exam scoring · 2026-09-30
- Code Security and Secret Protection products · 2026-09-30
- GitHub security features · 2026-09-30
- Dependabot alerts and updates · 2026-09-30
- Dependency review · 2026-09-30
- Code scanning · 2026-09-30
- Resolve exposed secrets · 2026-09-30
- Secret validity checks · 2026-09-30
- Dependency review thresholds and enforcement · 2026-09-30
- Secret scanning · 2026-09-30
- Fixing and dismissing code alerts · 2026-09-30
- Delegated dismissal · 2026-09-30
- Custom pattern dry runs · 2026-09-30
- Pattern changes and alert lifecycle · 2026-09-30
- Configuration status and enforcement · 2026-09-30
- SARIF fingerprints and paths · 2026-09-30
- Default and advanced setup · 2026-09-30
- CodeQL build modes · 2026-09-30
- Bypass versus exemptions · 2026-09-30
- User and repository push protection · 2026-09-30
- SPDX dependency inventory · 2026-09-30
- Campaign tracking · 2026-09-30
- Missing dependencies · 2026-09-30
- Dependency detection methods · 2026-09-30
- Auto-triage and reopening · 2026-09-30
- Custom triage scope · 2026-09-30
- Overview scope and permissions · 2026-09-30
- Dataflow and alert context · 2026-09-30
- Organization rollout · 2026-09-30
- CodeQL CLI analysis and categories · 2026-09-30
- EPSS score versus percentile · 2026-09-30
- Dependabot grouping · 2026-09-30
- Advisories and weaknesses · 2026-09-30
- Scan health and coverage · 2026-09-30
- Production context for prioritization · 2026-09-30
- Configuration API accepted versus applied · 2026-09-30
- Commit-specific dependency snapshots · 2026-09-30
- Asynchronous SBOM export and retiring endpoint · 2026-09-30
- Private registry access · 2026-09-30
What you will explore
0 / 7Products, scope, and prevention
Choose complementary controls and define the population represented by evidence.
Credentials, response, and exceptions
Distinguish detection, validity, containment, and secret-alert closure.
Dependencies, inventory, and merge prevention
Assess actual dependencies and apply updates with compatibility evidence.
CodeQL, coverage, and SARIF results
Choose suitable analysis and interpret results without confusing execution with coverage.
Priorities, campaigns, and exceptions
Turn alerts into remediation decisions with context and accountability.
Validation and production handover
Confirm coverage and track the fix through to affected runtime.
Administration and effective policy application
Confirm central-policy outcomes on each in-scope repository.