nerdexam
Microsoft

GH-500 · Question #118

Using advanced setup, which code scanning configuration would help detect vulnerabilities before they are added to a shared branch?

This question's answer choices and correct answer were not rendered - all four options show only 'on:' without the accompanying YAML trigger values, and the correct answer field is empty, making a full per-choice analysis impossible.

Configure and use Code Scanning with CodeQL

Question

Using advanced setup, which code scanning configuration would help detect vulnerabilities before they are added to a shared branch?

Options

  • Aon:
  • Bon:
  • Con:
  • Don:

Why each option

This question's answer choices and correct answer were not rendered - all four options show only 'on:' without the accompanying YAML trigger values, and the correct answer field is empty, making a full per-choice analysis impossible.

Aon:

Choice content was not provided in the question data - the YAML trigger value after 'on:' is missing.

Bon:

Choice content was not provided in the question data - the YAML trigger value after 'on:' is missing.

Con:

Choice content was not provided in the question data - the YAML trigger value after 'on:' is missing.

Don:

Choice content was not provided in the question data - the YAML trigger value after 'on:' is missing.

Concept tested: GitHub Advanced Security code scanning workflow trigger configuration

Source: https://docs.github.com/en/code-security/code-scanning/creating-an-advanced-setup-for-code-scanning/configuring-advanced-setup-for-code-scanning

Topics

#Code Scanning#GitHub Actions#Pre-merge checks#Vulnerability detection

Community Discussion

No community discussion yet for this question.

Full GH-500 Practice