What is the best method to ensure all new code is scanned for vulnerabilities?
A.
Add the extended suite.
B.
Configure code owners.
C.
Set up a security policy.
D.
Configure code scanning.
The Answer Is:
D
This question includes an explanation.
Explanation:
To systematically analyze newly introduced source code for security weaknesses, you should configure code scanning. GitHub code scanning can use CodeQL or supported third-party analysis tools and can run automatically when developers push changes or create pull requests. This places vulnerability detection directly into the development workflow rather than depending on manual review. The extended CodeQL query suite broadens the set of queries executed, but it only has an effect after code scanning itself is configured. CODEOWNERS determines who reviews specific paths and does not perform vulnerability analysis. A security policy explains how vulnerabilities should be reported but does not scan source code. Therefore, enabling and properly configuring code scanning is the foundational mechanism for ensuring new code is automatically analyzed.
GH-500 PDF/Engine
Printable Format
Value of Money
100% Pass Assurance
Verified Answers
Researched by Industry Experts
Based on Real Exams Scenarios
100% Real Questions
Get 70% Discount on All Products,
Use Coupon: "coponace"