GitHub Advanced Security (GHAS) Certification Exam Practice Test

112 questions available

Build your confidence for GitHub Advanced Security (GHAS) Certification Exam. Practice the concepts, understand the answers, and strengthen your knowledge one question at a time.

Try a sample question
Try 5 free questions
No account needed. A free account includes 20 questions for this exam.
Certification exam
60 Exam questions
2 hours Time Limit
Advanced Level
Your practice
112 Practice questions
1 hour 52 minutes Practice Time
Try 5 free questions
No account needed. A free account includes 20 questions for this exam.
The bar to clear 70 Published passing score for this certification.
Explore exam topics
GitHub112 practice questions
Blueprint verifiedChecked against GitHub official objectivesMetadata verified 2026-06-07How we verify

Exam overview and details

The GitHub Advanced Security (GHAS) Certification Exam is a professional credential that validates comprehensive expertise in implementing, managing, and scaling GitHub's integrated application security suite. This certification demonstrates a practitioner's ability to leverage CodeQL for variant analysis and custom query writing, configure and operationalize secret scanning and dependency review, implement security policies with CodeQL query packs, and manage the end-to-end security workflow within GitHub's ecosystem. Earning this certification signifies a deep, practical understanding of shifting security left in the software development lifecycle (SDLC) and using automation to identify and remediate vulnerabilities before they reach production. It is designed for security engineers, DevOps professionals, and developers responsible for securing codebases at scale, proving competency in one of the industry's most widely adopted developer security platforms. Holders of this credential are recognized for their skill in transforming security from a gatekeeping function to an integrated, developer-friendly practice.

Sample Questions

Choose an answer and explore the explanation to see how practice works.

Use Code Scanning with CodeQL

Blue Yonder Labs stores CodeQL configuration for firmware-dashboard in .github/codeql/codeql-config.yml. Where can the workflow reference it? The decision is being made during a June 2025 control review, and the team must choose the most defensible next action.

Use Code Scanning with CodeQL

Fabrikam Health runs CodeQL CLI for C# in an external CI system for claims-portal. Which sequence is correct? The decision is being made during a September 2024 control review, and the team must choose the most defensible next action.

Configure and Use Secret Scanning

Litware Games sees a secret scanning alert in matchmaking-service for a Slack webhook URL. The developer deleted the line in a follow-up commit but did not contact the provider. What is the best next step? The decision is being made during a September 2024 control review, and the team must choose the most defensible next action.

Domain 3: Configure and use dependency management

Litware Games wants Dependabot to open pull requests only for security fixes in matchmaking-service, not routine version bumps. Which feature should they enable? The decision is being made during a March 2025 control review, and the team must choose the most defensible next action.

Configure and Use Secret Scanning

central security needs a small group outside repository admins to receive secret scanning alerts for risk-scoring. Which configuration is most appropriate? The decision is being made during a November 2025 control review, and the team must choose the most defensible next action.

Career Opportunities & Salary

Median salary: $135,980– Software Developers

Source: BLS Occupational Employment and Wage Statistics, May 2025 -- Software Developers (SOC 15-1252), US national. Occupation median, not a certification salary. (2025)

Software Developers

Exam insights and study advice

In today's software-driven economy, securing the software supply chain is a top priority for organizations worldwide. The GitHub Advanced Security certification provides tangible, industry-recognized validation of your skills in this critical domain. It directly impacts career advancement by positioning you as a subject matter expert capable of leading DevSecOps initiatives, reducing organizational risk, and enabling secure development velocity. This certification is highly regarded by employers seeking to build robust application security programs, making certified professionals highly competitive for roles such as Application Security Engineer, DevSecOps Lead, and Security-focused Platform Engineer. It demonstrates not just theoretical knowledge, but the practical ability to implement and manage the security tools used by millions of developers daily.

What this exam covers

Use the published domain weights to plan your study. Practice results do not predict your certification exam score.

01Configure and Use Code Scanning

25%

02Configure and Use Dependency Review and Dependabot Alerts

20%

03Configure and Use Secret Scanning

20%

04Use Code Scanning with CodeQL

20%

05Describe the GitHub Advanced Security Features and Functionality

10%

06Describe GitHub Advanced Security Best Practices, Results, and How to Take Corrective Measures

5%

Exam Details GitHub-GHAS | $99 USD | 2 hours

Exam Code GitHub-GHAS
Vendor GitHub
Exam Cost $99 USD
Passing Score 70
Time Limit 2 hours
Exam questions 60
Question TypesMultiple Choice, Multiple Select, Drag and Drop
Retake Policy Wait 24 hours between attempts. Full exam fee for retake ($99).
Exam Format Linear (online proctored)
Online Proctoring Available
Available In
English

Frequently Asked Questions

What are the prerequisites for taking the GitHub Advanced Security GHAS certification exam?

How does this certification differ from general GitHub or DevOps certifications?

What is the typical format of the exam, and how is it delivered?

What are the key career roles that benefit from this certification?

How should I prepare for the hands-on aspects of the exam?