GH-500 Exam Guide: How to Prepare for GitHub Advanced Security
GH-500 validates whether you can use GitHub Advanced Security to protect code, secrets, and dependencies across the software development lifecycle. Microsoft describes the intended candidate as someone familiar with GitHub fundamentals, CI/CD, and secure-development concepts, with practical GHAS experience. This guide helps you decide whether your current experience is sufficient, which domains deserve the most study time, how to organize hands-on preparation, and what to verify before scheduling the assessment.
Is GH-500 the right exam for you?
GH-500 is intended for candidates who already work with GitHub Advanced Security rather than people encountering GitHub security features for the first time. The best preparation decision is to compare your real responsibilities with the published candidate profile before buying training or booking an assessment.
Microsoft positions the certification at intermediate level and associates it with Administrator, Developer, DevOps Engineer, Solution Architect, and Student roles. Those labels describe possible audiences, not prerequisites. The more useful question is whether you can connect security configuration with development workflows and operational decisions.
The official profile expects experience securing code, secrets, and dependencies throughout the software development lifecycle. It also describes candidates who can configure security features, triage and remediate alerts, and apply prevention-first practices through policies, workflows, and automation.
That profile favors breadth. A developer who knows CodeQL but has never considered organization-level administration may need to strengthen the administration and operations domains. An administrator who can enable features but cannot explain how developers should respond to alerts may need more work on remediation and secure-development practice.
Use this readiness test before selecting a study plan: can you explain what problem each major GHAS capability addresses, identify where it is configured, interpret the resulting alert or finding, and choose a sensible remediation or prevention action? If several answers are uncertain, begin with guided learning and practical configuration rather than memorization.
What does GH-500 measure?
The current blueprint contains six domains covering the GHAS ecosystem, Secret Protection, supply chain security, Code Security, security operations, and administration. Treat the percentages as planning guidance, and always study each percentage with its official domain label attached.
Domain 1, Describe GitHub Security Suites, Features, and Ecosystem, represents 15–20% of the assessed content. This is the orientation layer: understand the suite structure, distinguish the main security capabilities, and relate them to secure software development.
Domain 2, Configure and Use Secret Protection (formerly secret scanning), represents 15–20% of the assessed content. Prepare to reason about the purpose of secret protection, the configuration choices available to an organization, and the handling of findings as part of an operational process.
Domain 3, Configure and Use Supply Chain Security (formerly Dependabot/Dependency Review), represents 15–20% of the assessed content. Study how dependency-related risk fits into development workflows and how teams can use security controls to reduce exposure before software reaches production.
Domain 4, Configure and Use Code Security (formerly Code Scanning with CodeQL), represents 10–15% of the assessed content. This domain is smaller by blueprint allocation, but it still requires you to understand how code-security findings support investigation and remediation.
Domain 5, Security Operations: Best Practices, Prioritization, and Remediation, represents 15–20% of the assessed content. This is where isolated feature knowledge must become operational judgment: deciding what deserves attention, how to handle findings, and how prevention and remediation work together.
Domain 6, GitHub Security Suites Administration, represents 10–15% of the assessed content. Study administration as a distinct responsibility, including how security capabilities are governed and used across the relevant GitHub environments.
The study guide says the bullets beneath each measured skill illustrate assessment coverage and that related topics may also appear. Therefore, do not treat the domain names as a complete list of possible prompts. Use them to organize study, then read the official study guide’s detailed skill statements as your checklist.
Most questions cover general availability features. The study guide also notes that Preview features may appear when they are commonly used. This makes current, official product documentation more valuable than old notes that present a historical feature state as universal.
How should you divide study time?
Start with the three domains carrying 15–20% allocations, then give deliberate review time to operations and administration. Do not ignore the 10–15% domains: the smaller blueprint allocation for Code Security or administration does not make either area optional.
A practical sequence is to begin with Domain 1, then study Domains 2, 3, and 4 as capability areas, followed by Domain 5 for operational decision-making and Domain 6 for governance. This order gives you a vocabulary before you compare features, then asks you to apply that knowledge to alerts and administration.
For each domain, create a four-column note rather than a glossary. Record the security problem, the relevant GHAS capability, the configuration or workflow decision, and the response to a resulting finding. This format discourages passive reading and exposes gaps such as knowing a feature name without knowing when to use it.
Spend additional time on any domain where your work experience is narrow. A person who works only on repositories may need more administration study. A person who configures organization policies may need more practice interpreting developer-facing findings. The blueprint should guide the baseline allocation; your experience should determine the adjustment.
Avoid using the percentages as a prediction of the exact number or format of questions. Microsoft publishes the weighting as assessed-content ranges, not as a promise of a fixed question distribution. Use the ranges to prevent major blind spots, not to justify skipping a domain.
What should you learn first about the GHAS ecosystem?
Build a capability map before memorizing feature terminology. Domain 1 asks you to understand how GitHub security suites, features, and the wider ecosystem fit together, so your first task is to distinguish code, secret, supply-chain, operational, and administrative concerns.
Write a one-sentence purpose statement for each of the three named protection areas. Secret Protection concerns exposed credentials or other sensitive values; Supply Chain Security concerns dependency risk; Code Security concerns weaknesses identified in source code. Keep the statements conceptual, then verify the product terminology in the official study guide.
Next, trace the same security concern through a simplified lifecycle: a developer changes code, automation evaluates it, a finding is produced, a team prioritizes it, and remediation is recorded or implemented. The point is not to invent a particular workflow. It is to understand why security controls must connect to development and operations rather than remain isolated settings.
Review how feature availability can differ between public repositories and enterprise environments, a distinction explicitly listed in the study-guide skills. When studying a feature, ask where it is available, who controls it, and what organizational context affects its use. Do not assume a repository-level experience represents every enterprise configuration.
Use the Security Overview as an organizing concept rather than a screen-by-screen memorization exercise. The certification page specifically highlights security teams’ ability to gain visibility into security posture and supply chain. Your notes should explain what a cross-organizational view helps a team decide.
How can you prepare for Secret Protection?
Study Secret Protection as a lifecycle: prevent exposure where possible, detect a suspected secret, understand the alert, and follow an appropriate remediation path. This is more useful than learning secret scanning as a switch that is simply enabled and forgotten.
Begin by defining the risk. A secret committed to a repository can create a security incident even when the commit is later changed, because historical content and downstream copies may remain relevant. Treat this as a study principle, not as a substitute for the official feature behavior or organization policy documentation.
Create a decision table for a hypothetical finding without using live credentials. Record whether the value appears sensitive, which repository or branch context matters, who should investigate, and what prevention or remediation action should follow. The exercise should teach disciplined handling without reproducing real secrets or relying on exam questions.
Then review the distinction between identifying a secret and resolving the underlying exposure. Detection answers whether a potentially sensitive value was found. Remediation requires a response appropriate to the credential, its use, and the surrounding system. Prevention asks how the development process can reduce recurrence.
A frequent mistake is to treat an alert as proof that the credential is still valid or to treat closing an alert as equivalent to rotating or revoking a credential. The exam preparation lesson is to separate finding management from incident response and to verify each product-specific behavior in current Microsoft Learn material.
How should you study Supply Chain Security?
Approach Supply Chain Security through dependency decisions: identify what the project relies on, understand the risk signal, evaluate the change in its development context, and choose a response that protects delivery without ignoring security. The official blueprint names this domain as 15–20% of assessed content.
Use a sample repository with a deliberately simple dependency set, or work from documented examples, and map the points where dependency risk can be surfaced during development. Note what a developer, reviewer, and security administrator each need to know. This helps you connect dependency controls with CI/CD and review practices.
Compare two situations in your notes: a newly proposed dependency change and a vulnerability discovered in an existing dependency. They may require different decisions, even though both concern the software supply chain. For each, identify the evidence needed, the responsible role, and the remediation or approval path.
Do not reduce this domain to the name of a single tool. The study guide uses the current label Supply Chain Security and identifies Dependabot and Dependency Review as former terminology. Learn the security outcome and workflow relationship, then use current official naming when you revise your notes.
A common pitfall is to assume that the presence of an automated alert automatically determines priority. Practice explaining why severity, exploitability, project exposure, release context, and available remediation information may affect triage. Keep product-specific rules grounded in the official documentation rather than inventing a universal ranking formula.
How should you prepare for Code Security?
Code Security represents 10–15% of the assessed content and was formerly described as Code Scanning with CodeQL. Study it as a way to identify weaknesses in source code and support an engineering response, not as a list of query names detached from development practice.
Start by learning the relationship between code analysis, the repository workflow, and the finding that reaches a developer or security team. For every concept, ask what is being analyzed, when the analysis occurs, where the result is reviewed, and what action turns a finding into reduced risk.
Practice reading a documented finding and writing a short response plan: confirm the affected code path, assess the context, identify a safe correction, and determine how the change should be verified. This is a preparation exercise, not a claim about a particular exam item or a guarantee of the exact assessment experience.
Review Code Security alongside Domain 5. Knowing that a finding exists is different from deciding whether it is urgent, how it should be assigned, and whether a recurring pattern calls for a policy or workflow change. That connection is central to prevention-first security.
Do not spend all your time on query syntax unless the official skills list or your job requires it. GH-500 covers a broader security capability and administration picture. Use the measured skills to decide how deep a technical subtopic should go.
How do you turn findings into security operations?
Domain 5 requires an operational mindset: findings must be triaged, prioritized, remediated, and used to improve prevention. Build a repeatable response model so that you can explain not only what a feature detects but also what a team should do next.
For each alert type, practice answering five questions: What is the security concern? How credible or relevant is the finding? What asset or workflow is affected? Who owns the response? What change prevents recurrence? The answers will differ by finding and environment, which is why rigid memorization is weak preparation.
Use small case studies that you write yourself. For example, compare an exposed secret, a vulnerable dependency, and a code weakness. For each case, identify the first investigation step, the likely owner, the remediation objective, and the longer-term control. Keep the examples fictional and avoid relying on leaked or purported assessment content.
A common mistake is to equate the most technically interesting finding with the highest priority. Operational prioritization should consider the affected software, business or deployment context, exploitability, confidence, and available remediation options. When a product-specific decision is involved, consult the current official guidance rather than treating this general framework as a published GHAS rule.
Review automation and policy concepts after you understand manual triage. Automation is most useful when you know which decision can be standardized and which cases require human review. This sequencing prevents you from learning workflows as arbitrary configuration steps.
What administration topics deserve focused review?
Domain 6 covers GitHub Security Suites Administration and represents 10–15% of assessed content. Prepare for it by thinking in terms of scope, control, visibility, and consistency across repositories or organizational environments rather than memorizing isolated settings.
Build an administration checklist for each security capability: who can configure it, where the setting applies, how developers discover findings, how security teams review posture, and what changes might affect existing workflows. Verify the product-specific answers in the current official materials.
Study administration together with the distinction between public-repository and enterprise availability identified in the study guide. A control that appears straightforward at repository level may have different implications when applied across an organization. Your notes should make the scope explicit every time you describe a setting.
Also connect administration to prevention-first practice. A useful administrator does more than activate features; the administrator helps establish consistent policies, usable workflows, and a path from finding to remediation. That is the bridge between Domain 6 and Security Operations.
Do not assume a course completion code or training attendance proves exam readiness. Microsoft lists GH-500T00-A as an intermediate course and provides instructor-led and self-paced study options, but the assessment still requires you to understand the measured skills and apply them to decisions.
Which official resources should anchor your preparation?
Use the Microsoft Learn certification page to verify current exam details, the GH-500 study guide to build your topic checklist, the practice assessment to gauge readiness, and the exam sandbox to learn the assessment interface. These resources serve different purposes and should not be treated as interchangeable.
The study guide is the central document for scope. Microsoft says it explains what to expect, summarizes topics that the exam might cover, and links to additional resources. Begin there, copy the six domain labels into your study tracker, and mark each detailed skill as understood, practiced, or unresolved.
The practice assessment is for diagnosis, not for collecting answers. Microsoft describes it as a way to review the style, wording, and difficulty of likely questions, assess readiness, identify preparation needs, and fill knowledge gaps. After each attempt, research why an answer is correct and why the alternatives do not fit.
Use the sandbox before exam day. The certification page says it lets candidates interact with different question types in the same user interface used during the exam. That makes it a practical way to reduce interface uncertainty without seeking live questions or unauthorized material.
The GH-500T00-A course is an optional structured path. Microsoft lists both instructor-led and self-paced study, with an intermediate level and a one-day course duration. Choose it if you need an organized introduction or prefer guided instruction; do not use the course label as evidence that every measured skill is mastered.
Ignore sites that promise passing through dumps, leaked questions, or memorized answer sets. They are not a substitute for security judgment, may be inaccurate as features change, and do not help you handle unfamiliar scenarios. Use official resources and legitimate practice instead.
What is a practical GH-500 study roadmap?
A four-stage roadmap works well: establish baseline knowledge, study the six domains, apply the concepts to workflows, and validate readiness. Set the length of each stage according to your experience rather than copying a fixed calendar.
Stage one is a gap assessment. Read the audience profile and six domain headings, then write what you can currently configure, explain, triage, and administer. Take the official practice assessment when you are ready to obtain a baseline. Do not interpret one result as a permanent prediction; use it to select the next topics.
Stage two is structured domain study. Work through Domain 1 first, then Secret Protection, Supply Chain Security, Code Security, Security Operations, and Administration. For each domain, produce the four-column notes described earlier and attach links to the official documentation you used. Resolve terminology changes such as Secret Protection and Supply Chain Security before final review.
Stage three is application. Build fictional cases that move from a code change to a security signal, then to triage, remediation, and prevention. Compare repository-level and broader organizational considerations where the study guide calls for that distinction. If you have access to an authorized GitHub environment, use it responsibly; otherwise, use Microsoft Learn exercises and documentation rather than improvising unsupported product behavior.
Stage four is readiness validation. Revisit every unresolved skill, repeat practice only after reviewing mistakes, and use the exam sandbox to become familiar with the interface. Your final review should emphasize distinctions you confuse, not topics you already recall easily.
A useful stopping rule is evidence-based: you can explain the purpose and scope of each domain, connect each security signal to a response, and justify administration or workflow choices without relying on a memorized answer. If you cannot do that, postpone scheduling and close the specific gap.
What exam delivery details should you verify?
Microsoft states that GH-500 is a proctored assessment, allows 100 minutes, and may include interactive components. Confirm the current scheduling information before registering because delivery policies, accommodations, and availability can change.
The listed languages are English, Spanish, Portuguese (Brazil), Korean, and Japanese. The study guide says localized versions may be updated approximately eight weeks after the English version, although Microsoft notes that this schedule is not guaranteed in every case.
If the exam is not available in your preferred language, the study guide says you can request an additional 30 minutes to complete it. Make the request through the official accommodation process and confirm the approval and scheduling requirements before relying on the adjustment.
The certification page says scheduling is through Pearson VUE and recommends registering with a personal Microsoft account. Microsoft warns that using an organizational work or school account can cause exam records to be lost and unrecoverable if you leave that organization. Treat account selection as a real administrative decision, not a last-minute formality.
The exam price is based on the country or region in which the exam is proctored. Check the official certification page for the amount applicable to your location rather than relying on a third-party listing.
Microsoft states that a score of 700 or greater is required to pass. That threshold should be used as an official requirement, not as a reason to target borderline practice results. Aim to understand the domains consistently before scheduling.
If you fail, Microsoft says you can retake the certification exam 24 hours after the first attempt; later retake intervals vary. Review the current retake policy and use any unsuccessful attempt as a diagnostic opportunity rather than immediately repeating the same preparation.
What mistakes commonly weaken preparation?
The most damaging mistakes are studying product names without workflows, skipping lower-weight domains, relying on stale terminology, and using practice material as an answer bank. Correct these by tying every note to a security problem, a scope, a decision, and a remediation or prevention action.
Mistake one is treating the blueprint as a complete syllabus. The study guide says the listed bullets illustrate assessment and that related topics may also be covered. Read the detailed guide and linked resources instead of preparing only from the six headings.
Mistake two is confusing detection with resolution. A finding is a signal that requires interpretation and action; it is not automatically a remediated risk. Make your notes describe ownership, investigation, correction, and prevention separately.
Mistake three is using old names without learning the current labels. Secret scanning is now represented in the blueprint as Secret Protection, Dependabot and Dependency Review are associated with Supply Chain Security, and Code Scanning with CodeQL is represented as Code Security. Learn both relationships so older course material does not confuse you.
Mistake four is overfitting to a single job role. GH-500 serves several role profiles, and the candidate description spans code, secrets, dependencies, operations, policies, workflows, and automation. Study outside your daily specialty until you can explain how the areas interact.
Mistake five is scheduling before checking logistics. Confirm language, account choice, proctoring details, accommodations if needed, price for your region, and current exam information on the official page. These checks are practical recommendations; the official requirements remain those published by Microsoft and GitHub.
What should you do next?
Your next action is to open the official GH-500 study guide, turn its six domains into a checklist, and mark each skill according to evidence rather than confidence. Then choose between self-paced study, the structured GH-500T00-A course, or a combination based on the gaps you find.
If your experience already includes GHAS configuration and alert response, begin with the practice assessment and use the results to target weak domains. If you lack that experience, start with the candidate profile and course or Learn material, then use fictional workflows to build decision-making ability before attempting repeated assessments.
Schedule only after you can move comfortably from a security concern to configuration, interpretation, remediation, and prevention. Before registration, verify the official delivery details and use a personal Microsoft account as recommended. This approach gives you a defensible preparation plan without depending on unauthorized exam content or unsupported promises.
Conclusion
GH-500 preparation is strongest when it combines blueprint-led coverage with practical security reasoning. Learn the six domains, give the 15–20% areas appropriate attention, connect findings to operations, and treat administration as part of secure delivery rather than a separate checklist. Use the official study guide, practice assessment, course options, and sandbox to identify and close gaps. Then verify the current scheduling and accommodation details before booking the assessment.
Related exams
- GH-100 exam — GitHub Administration
- GH-200 exam — GitHub Actions Exam
- GH-300 exam — GitHub Copilot Exam
- GH-900 exam — GitHub Foundations