Detailed Exam Domain CoverageDomain 1: Describe the GHAS security features and functionality (15%)Core GHAS security tools: Code Scanning, Secret Scanning, Dependabot, and Dependency Review.Integration of GHAS into the software development lifecycle (SDLC).Differentiating between GitHub security alerts and remediation actions.Domain 2: Configure and use secret scanning (15%)Enabling secret scanning at the repository and organization levels.Configuring push protection to block secret leaks in pull requests.Managing secret scanning alerts: triage, revocation, and remediation.Domain 3: Configure and use Dependabot and Dependency Review (35%)Setting up Dependabot alerts and security updates for vulnerable dependencies.Using Dependency Review to approve or reject dependency changes in pull requests.Interpreting the dependency graph and understanding vulnerability identification.Configuring automatic version updates and customizing update schedules.Domain 4: Configure and use Code Scanning with CodeQL (25%)Configuring Code Scanning workflows using GitHub Actions.Running CodeQL analysis and interpreting security findings.Setting up alert policies and integrating Code Scanning results with security dashboards.Customizing CodeQL queries for project-specific security rules.Domain 5: Describe GitHub Advanced Security best practices, results, and how to take corrective measures (10%)Applying GHAS best practice recommendations for a secure SDLC.Prioritizing and remediating findings based on severity, exploitability, and impact.Measuring security program effecti
What you'll learn
Understand GitHub Advanced Security features and tools
Configure secret scanning and manage alerts
Utilize Dependabot for dependency management
Set up Code Scanning with CodeQL and customize queries
Apply best practices for a secure software development lifecycle
Course objectives
Provide in-depth knowledge of GitHub security features
Enable effective configuration of security tools
Improve capabilities in managing vulnerabilities and alerts