How much does the GitHub Advanced Security Certification (GH-500) exam cost?
The exam costs $99 USD
What are the prerequisites for the GitHub Security?
You should be a developer or security professional who understands GitHub's platform, including repositories, branches, pull requests, and GitHub Actions. Familiarity with application security concepts — SAST, dependency scanning, secret management — is important. If you've never used GitHub Advanced Security features like code scanning, Dependabot, or secret scanning in a real repository, you need hands-on time before the exam.
How many questions are on the GitHub Security exam?
The exam has 60 questions to be completed in 120 minutes. Multiple-choice and scenario-based questions. Expect questions about configuring GHAS features at the organization and enterprise level, interpreting code scanning alerts, managing Dependabot PRs, writing custom CodeQL queries, and configuring secret scanning patterns. Some questions present GitHub Actions workflow files for code scanning configurations.
What is the passing score for the GitHub Security?
Pass/fail with a 70% cut score. Delivered through PSI. Results are available after completing the exam.
How long should I study for the GitHub Security?
Six to eight weeks if you actively manage GHAS in an organization. If you've used basic Dependabot and code scanning but haven't written custom CodeQL queries or configured enterprise-level GHAS settings, add a few weeks for those areas. CodeQL is the domain that requires the most dedicated study time for most candidates.
Can I take the GitHub Security exam online?
Delivered through PSI with online proctoring and testing center options. Standard requirements: webcam, microphone, clean workspace, stable internet. 120 minutes gives comfortable pacing.
How long is the GitHub Security certification valid?
Valid for three years. Renewal requires retaking the current exam. GitHub Advanced Security features evolve quickly, so the exam content updates to reflect new capabilities.
What is the pass rate for the GitHub Security?
GitHub doesn't publish pass rates. The exam is newer and the candidate pool tends to be security-focused professionals. Community reports suggest solid pass rates among candidates who've actively managed GHAS in production. CodeQL is the domain that most commonly needs additional study.
Is the GitHub Security certification worth it in 2026?
DevSecOps is one of the hottest specializations in software engineering, and GitHub Advanced Security is the shift-left security tooling built into the world's largest code hosting platform. This cert proves you can implement security automation directly in the development workflow. It's particularly valuable at organizations that use GitHub Enterprise Cloud or Server, where GHAS is a premium add-on that needs skilled configuration.