GitHub Actions (GH-200) Exam Questions GitHub Actions (GH-200) Exam Questions

Page content

Comprehensive list of Free GitHub Actions (GH-200) exam questions, grouped by the official exam skill domains, curated for cracking the exam with confidence.

Disclaimer: GitHub, GitHub Actions and GitHub Copilot are trademarks of GitHub, Inc. These exam questions are neither endorsed by nor affiliated with GitHub or Microsoft. These are not the official GitHub Actions exam questions/dumps. These questions are created from the GitHub documentation. They cover all 5 skill domains of the GitHub Actions (GH-200) exam, following the skills outline updated in January 2026, and once you go through these questions and their concepts, you are more than ready to crack the exam in first attempt.

Free Online Practice Exam


Take all 207 questions as a timed online practice exam, free:-

Overview


  1. This is an intermediate-level certification validating your skills with GitHub Actions: writing and managing workflows (triggers, jobs, matrices, variables, secrets, artifacts and caching), reading and troubleshooting runs, building and publishing JavaScript, Docker and composite actions, managing runners and policies across an enterprise, and securing and optimizing automation.
  2. It suits developers, DevOps engineers and platform administrators who automate builds, tests and deployments on GitHub. Hands-on experience writing workflow YAML is recommended.
  3. Exam code is GH-200, and passing it earns the GitHub Certified: GitHub Actions credential. The exam is delivered through Microsoft Learn (Pearson VUE), online proctored or at a test center, in English, Spanish, Portuguese (Brazil), Korean and Japanese. The price depends on your country or region.
  4. Exam duration is 100 minutes. GitHub doesn’t publish a fixed question count; questions are multiple choice and multiple select, many with workflow YAML to read.
  5. The passing score is 700 (on a scale of 1–1000).
  6. The exam covers 5 skill domains (see the weighting table below), following the skills measured as of January 2026. Actions changes regularly (runner images, action versions such as actions/checkout, artifact and cache behavior), so check the docs for the latest behavior.
  7. Official certification page, GH-200 study guide and GitHub Actions documentation for more details.

207 Practice Questions


# Domain Weight Questions below
1 Author and manage workflows 20–25% 75
2 Consume and troubleshoot workflows 15–20% 39
3 Author and maintain actions 15–20% 49
4 Manage GitHub Actions for the enterprise 20–25% 33
5 Secure and optimize automation 10–15% 11

Domain 1: Author and manage workflows (20–25%)

Which YAML keyword defines the events that trigger a workflow?

⬜ on
⬜ trigger
⬜ event
⬜ workflow

What is the shortest interval you can use when scheduling a GitHub Actions workflow?

⬜ Five minutes
⬜ One hour
⬜ Thirty seconds
⬜ One day

What do you need in order to run a private repository’s workflow manually through the GitHub REST API?

⬜ An access token, such as a personal access token
⬜ A username and password
⬜ An API key
⬜ An SSH key

Which keyword makes a step run only when a given expression or condition is true?

⬜ if
⬜ when
⬜ condition
⬜ only

Which of these activities can trigger a workflow? (select three)

⬜ An issue being opened
⬜ A commit being pushed to the repository
⬜ A discussion being created
⬜ Someone being invited to the repository

When this workflow is triggered, what does the Print name step output?
name: Java CI with Maven

env:
  NAME: 'My Action'

on:
  push:
    branches: [ "main" ]

jobs:
  build:
    env:
      JAVA_VERSION: '11'

    runs-on: ubuntu-latest

    steps:
    - uses: actions/checkout@v7
    - name: Set up JDK ${{ env.JAVA_VERSION }}
      uses: actions/setup-java@v4
      with:
        java-version: ${{ env.JAVA_VERSION }}
        distribution: 'temurin'
        cache: maven
    - name: Build with Maven
      run: mvn -B package --file pom.xml
    - name: Print name
      run: echo "Hello $NAME. $BUILD. Using Java Version $JAVA_VERSION"
      env:
        BUILD: 'We are currently running the Build job'

⬜ Hello My Action. We are currently running the Build job. Using Java Version 11
⬜ Hello My Action. $BUILD. Using Java Version 11
⬜ Hello $NAME. $BUILD. Using Java Version $JAVA_VERSION
⬜ The run fails because of a syntax error.

A DevOps engineer is looking for a repository’s GitHub Actions workflow files. Where should they look?

⬜ The .github/workflows directory of the repository
⬜ The repository’s README.md file
⬜ The repository’s Settings > Actions page on GitHub
⬜ The .github directory of the repository

Which are valid ways to reference a version of the checkout action in a workflow? (select three)

⬜ - uses: actions/checkout@v7
⬜ - uses: actions/checkout@main
⬜ - uses: actions/checkout@8f4b7f84864484a7bf31766abe9204da3cbe65b3
⬜ - uses: https://github.com/actions/checkout

In GitHub Actions, what role do steps play?

⬜ They are the individual tasks that make up a job.
⬜ They are another name for workflows.
⬜ They refer to the overall execution of actions.
⬜ They are part of the Marketplace integration process.

What is the main purpose of making jobs depend on each other in a workflow?

⬜ To set the order in which jobs run
⬜ To make jobs run at the same time, independently
⬜ To enforce conditional logic based on job outcomes
⬜ To control the workflow’s overall concurrency settings

Which default environment variables can’t be overwritten through the GITHUB_ENV file?

⬜ GITHUB_* and RUNNER_*
⬜ CI
⬜ JAVA_HOME
⬜ None; all default environment variables can be overwritten.

How can you customize how long a workflow artifact is kept?

⬜ Set a custom retention period for an individual artifact with actions/upload-artifact.
⬜ You can’t; artifact retention isn’t configurable.
⬜ Retention can only be set at the organization level.
⬜ Custom retention periods are applied automatically to every repository.

What should you know about workflow status badges for a private repository?

⬜ They aren’t accessible externally, so they can’t be embedded in or linked from outside sites.
⬜ They’re turned off by a GitHub Actions limitation and never render.
⬜ They’re disabled by default and have to be turned on in the repository settings.
⬜ They’re visible only to repository collaborators who have admin access.

A workflow runs on branch_protection_rule events, but it shouldn’t run when a branch protection rule is deleted. Which configuration does that?

⬜

on:
  branch_protection_rule:
    types: [created, edited]

⬜

on:
  branch_protection_rule:
    types: [deleted]

⬜

on:
  branch_protection_rule:
    types: [created, edited, deleted]

⬜

on:
  branch_protection_rule:
    notTypes: [deleted]
Which statement correctly describes YAML indentation rules for workflow files?

⬜ Newlines and indentation are significant, as in Python, but unlike Python, YAML doesn’t allow literal tab characters for indentation.
⬜ YAML follows exactly the same rules as Python, including allowing tab characters for indentation.
⬜ YAML follows JSON syntax strictly, allows only spaces and doesn’t allow newlines.
⬜ YAML allows literal tab characters for indentation, as Python does.

Which configuration triggers a workflow for pull requests?

⬜

on:
  pull_request:
    branches:
      - main

⬜

on: push

⬜

on: fork

⬜

on:
  pull_request:
    types:
      - main
How many PowerShell commands does this workflow run on the Windows runner?
name: Run commands Windows
on:
  push:
    branches: [ main ]

jobs:
  Run-PSScriptAnalyzer-on-Windows:
    name: Run PSScriptAnalyzer on Windows
    runs-on: windows-latest
    steps:
      - uses: actions/checkout@v7
      - name: Install PSScriptAnalyzer module
        shell: pwsh
        run: |
          Set-PSRepository PSGallery -InstallationPolicy Trusted
          Install-Module PSScriptAnalyzer -ErrorAction Stop
      - name: Get list of rules
        shell: pwsh
        run: |
          Get-ScriptAnalyzerRule

⬜ 3
⬜ 2
⬜ 4
⬜ 1

How many jobs does this workflow run?
jobs:
  matrix-job:
    runs-on: ubuntu-latest
    strategy:
      matrix:
        animal: [cat, dog, bear]
        color: [black, brown]
    steps:
      - run: echo "Hello ${{ matrix.color }} ${{ matrix.animal }}"

⬜ 6
⬜ 3
⬜ 2
⬜ 0

What is the jobs section of a GitHub Actions workflow for?

⬜ To organize the work into jobs and define the steps they run, in parallel or in sequence
⬜ To define environment variables
⬜ To set the workflow’s name
⬜ To declare the events that trigger the workflow

How can you make a workflow run on a schedule that covers weekdays only?

⬜ Use on: schedule with a cron expression.
⬜ Add a condition to the workflow YAML that checks for weekdays.
⬜ Set the schedule in the repository settings.
⬜ Use an on: schedule: weekdays setting.

Which default environment variable holds the operating system of the runner running the job?

⬜ RUNNER_OS
⬜ RUNNER_ARCH
⬜ GITHUB_RUNNER_OS
⬜ RUNNER_DEBUG

⬜ Treat them as case-sensitive.
⬜ Ignore case, because GitHub Actions handles it automatically.
⬜ Use only uppercase letters in the names.
⬜ Rely on whatever the operating system does.

How do events, workflows, jobs and steps work together in a typical run?

⬜ An event triggers a workflow, which runs one or more jobs, each made up of one or more steps.
⬜ Steps start actions, which run inside workflows and produce runs within one or more jobs.
⬜ Runs start actions, which are made up of steps run inside jobs and workflows.
⬜ Jobs start runs, which are made up of actions with individual steps in a shared workflow.

What is essential when deploying a release to a cloud provider with a GitHub Actions workflow?

⬜ Defining the deployment steps in the workflow’s YAML file
⬜ Leaving the workflow YAML file out of the repository
⬜ Setting up several workflows in separate repositories
⬜ Avoiding environment variables during deployment

How does the cache action handle a cache miss?

⬜ It creates a new cache automatically if the job completes successfully.
⬜ It stops the workflow when a cache miss happens.
⬜ It needs someone to create the new cache manually.
⬜ It looks for a cache in other repositories.

How can you find the expiration date of a specific artifact?

⬜ Call the REST API and check the artifact’s expiration date.
⬜ Use the Artifacts tab on the repository page.
⬜ Open the Actions tab, click the workflow, and read the expiration in the summary.
⬜ You can’t find an artifact’s expiration date.

How do you define a matrix for a job?

⬜ Use the matrix keyword inside the job’s strategy.
⬜ Use the matrix keyword inside runs-on.
⬜ Use a variables section in the job definition.
⬜ Use the matrix keyword at the workflow level.

For a push or pull_request event, what happens if you define both a branches filter and a paths filter?

⬜ The workflow runs only when both the branches and paths filters are satisfied.
⬜ The workflow runs when either filter is satisfied, but applies only the one that matched.
⬜ The workflow doesn’t run when both filters are satisfied.
⬜ The workflow runs when either filter is satisfied.

Which configuration runs a workflow when a commit is pushed to a feature branch?

⬜

on:
  push:
    branches:
      - 'feature/*'

⬜

on: push

⬜

on:
  push:
    types:
      - 'feature'

⬜

on:
  commit:
    branches:
      - 'feature/*'
Jeff is troubleshooting why this workflow never runs. What is wrong with it?
name: learn-github-actions
run-name: ${{ github.actor }} is testing out GitHub Actions 🚀
jobs:
  Explore-GitHub-Actions:
    runs-on: ubuntu-latest
    steps:
      - run: echo "🎉 The job was automatically triggered by a ${{ github.event_name }} event."
      - run: echo "🐧 This job is now running on a ${{ runner.os }} server hosted by GitHub!"
      - run: echo "🔎 The name of your branch is ${{ github.ref }} and your repository is ${{ github.repository }}."
      - name: List files in the repository
        run: |
          ls ${{ github.workspace }}

⬜ It’s missing the on key that says which events trigger it.
⬜ The name key isn’t allowed inside the steps section.
⬜ Every run key must be preceded by its own step key.
⬜ The indentation is invalid.

Laura wants a step in a job on ubuntu-latest that adds the /tmp directory to the PATH for the job’s later steps. Which step does this?

⬜ - run: echo "/tmp" >> $GITHUB_PATH
⬜ - run: echo "/tmp" >> $GITHUB_STEP_SUMMARY
⬜ - run: echo "/tmp" >> $GITHUB_OUTPUT
⬜ - run: echo "/tmp" >> $GITHUB_ENV

Which workflow correctly publishes a Node.js package to GitHub Packages when a release is published?

⬜

name: Node.js Package
on:
  release:
    types: [published]
jobs:
  publish:
    runs-on: ubuntu-latest
    permissions:
      contents: read
      packages: write
    steps:
      - uses: actions/checkout@v7
      - uses: actions/setup-node@v4
        with:
          node-version: '20.x'
          registry-url: 'https://npm.pkg.github.com'
      - run: npm ci
      - run: npm publish
        env:
          NODE_AUTH_TOKEN: ${{ secrets.GITHUB_TOKEN }}

⬜

name: Node.js Package
on:
  release:
    types: [published]
jobs:
  publish:
    runs-on: ubuntu-latest
    permissions:
      contents: read
      packages: write
    steps:
      - uses: actions/checkout@v7
      - uses: actions/setup-node@v4
        with:
          node-version: '20.x'
      - run: npm ci
      - run: npm publish
        env:
          NODE_AUTH_TOKEN: ${{ secrets.GITHUB_TOKEN }}

⬜

name: Node.js Package
on:
  release:
    types: [published]
jobs:
  publish:
    runs-on: ubuntu-latest
    permissions:
      contents: read
      packages: write
    steps:
      - uses: actions/checkout@v7
      - uses: actions/setup-node@v4
        with:
          node-version: '20.x'
          registry-url: 'https://npm.pkg.github.com'
      - run: npm ci
      - run: npm publish

⬜

name: Node.js Package
on:
  release:
    types: [published]
jobs:
  publish:
    runs-on: ubuntu-latest
    permissions:
      contents: read
      packages: write
    steps:
      - uses: actions/checkout@v7
      - run: npm ci
      - run: npm publish
        env:
          NODE_AUTH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
Where can you define custom environment variables for a workflow?

⬜ Directly in the workflow file
⬜ In the main code file
⬜ Only as command-line arguments
⬜ In your profile settings

How do you specify that one job depends on another?

⬜ Define the dependency in the workflow YAML with the needs keyword.
⬜ Use a depends-on keyword in each job.
⬜ Pass environment variables between the jobs.
⬜ Put the jobs in separate workflow files.

What is the main purpose of using workflow commands in a run step?

⬜ To send instructions and information to the runner
⬜ To run custom scripts on the runner
⬜ To tell the workflow to move on to the next step
⬜ To define environment variables for the entire workflow

What does continue-on-error do on a step?

⬜ It lets the job carry on even if that step fails.
⬜ It defines steps that run only when there’s an error.
⬜ It makes the step always run, whatever errors happened earlier.
⬜ It sets conditions for retrying the step.

What does jobs.<job_id>.runs-on do in a workflow?

⬜ It specifies the type of machine and operating system the job runs on.
⬜ It declares which version of the GitHub Actions runner application to use.
⬜ It sets up conditional statements for running the job.
⬜ It defines environment variables for the job.

What is the workflow_dispatch event for?

⬜ Running the workflow manually
⬜ Running the workflow when any branch is pushed
⬜ Running the workflow on a set schedule
⬜ Running the workflow for pull requests

Which key in a job step specifies the action to run?

⬜ uses
⬜ action
⬜ execute
⬜ perform

What is the standard syntax for using the GITHUB_TOKEN in a workflow?

⬜ ${{ secrets.GITHUB_TOKEN }}
⬜ ${{ GITHUB_TOKEN }}
⬜ ${{ mySecrets.GITHUB_TOKEN }}
⬜ ${{ GITHUB_TOKEN.secrets }}

How can a workflow run a script that’s stored in your repository?

⬜ Use the run keyword with the script’s path on the runner.
⬜ Copy the script to the runner by hand and run it.
⬜ Use a third-party tool to trigger the script.
⬜ Paste the script’s contents directly into the workflow file.

When are service containers created and removed?

⬜ They’re created for each job and removed when the job finishes.
⬜ They’re created when the workflow starts and removed when it ends.
⬜ They’re created with the repository and removed when it’s archived.
⬜ They’re created on demand whenever a step needs one.

What does restore-keys do in the cache action?

⬜ It provides fallback keys to try when the main key misses.
⬜ It sets the location of the cached files.
⬜ It turns on cross-OS caching.
⬜ It reports whether a cache hit happened.

Which parameter can you add to a workflow status badge URL to show the status for a specific branch?

⬜ ?branch=BRANCH-NAME
⬜ ?commit=COMMIT-HASH
⬜ ?workflow=WORKFLOW-NAME
⬜ ?branch=WORKFLOW-NAME

What is the maximum number of jobs a matrix can generate in one workflow run?

⬜ 256
⬜ 128
⬜ 512
⬜ Unlimited

What stops a user from approving a deployment for a workflow run they started themselves?

⬜ The target environment has Prevent self-review turned on.
⬜ The user doesn’t have enough permissions.
⬜ The user’s account isn’t on a GitHub Pro or Enterprise plan.
⬜ The job isn’t configured correctly.

Which configuration runs a workflow for check_run webhook activity?

⬜

on:
  check_run:
    types: [created, completed]

⬜

on:
  check_run:
    types: [started]

⬜

on:
  check_run:
    filter: [requested]

⬜

on:
  check_run:
    type: [closed]
Which of these runs a workflow when an issue is opened?

⬜ Any of the three configurations shown in the other options
⬜

on:
  issues:
    types:
      - opened

⬜

on:
  issues:
    types: [opened]

⬜

on:
  issues
What is the URL of the GitHub Container registry?

⬜ ghcr.io
⬜ github.com
⬜ docker.io
⬜ github.com/container

Which configurations correctly run the job only when the workflow was triggered from the main branch? (select two)

⬜

name: CI
on: push
jobs:
  prod-check:
    if: github.ref == 'refs/heads/main'
    runs-on: ubuntu-latest
    steps:
      - run: echo "the main branch triggered this workflow"

⬜

name: CI
on: push
jobs:
  prod-check:
    if: ${{ github.ref == 'refs/heads/main' }}
    runs-on: ubuntu-latest
    steps:
      - run: echo "the main branch triggered this workflow"

⬜

name: CI
on: push
jobs:
  prod-check:
    if: github.ref == 'main'
    runs-on: ubuntu-latest
    steps:
      - run: echo "the main branch triggered this workflow"

⬜

name: CI
on: push
jobs:
  prod-check:
    if: github.ref == main
    runs-on: ubuntu-latest
    steps:
      - run: echo "the main branch triggered this workflow"
Which four lines does this workflow print, across both jobs?
name: my_color_workflow
on:
  workflow_dispatch:
env:
  favorite_color: orange
jobs:
  my_color_1:
    runs-on: ubuntu-latest
    env:
      favorite_color: blue
    steps:
      - name: Set the color
        id: step_one
        env:
          favorite_color: green
        run: |
          echo "my_color=$favorite_color" >> "$GITHUB_ENV"
      - name: echo the color
        id: step_two
        run: |
          echo "🎉 My color is ${{ env.my_color }}"
          echo "🎉 My favorite color is ${{ env.favorite_color }}"
  my_color_2:
    runs-on: ubuntu-latest
    steps:
      - name: echo the color
        id: step_one
        run: |
          echo "🎉 My color is ${{ env.my_color }}"
          echo "🎉 My favorite color is ${{ env.favorite_color }}"

⬜

🎉 My color is green
🎉 My favorite color is blue
🎉 My color is
🎉 My favorite color is orange

⬜

🎉 My color is green
🎉 My favorite color is blue
🎉 My color is green
🎉 My favorite color is orange

⬜

🎉 My color is green
🎉 My favorite color is orange
🎉 My color is green
🎉 My favorite color is orange

⬜

🎉 My color is green
🎉 My favorite color is blue
🎉 My color is green
🎉 My favorite color is green
What is a common reason to use custom environment variables?

⬜ To store and reuse non-sensitive configuration values
⬜ To control the flow of execution in the code
⬜ To define global constants for the entire project
⬜ To specify file paths for input and output

Which statement correctly describes how default environment variables can be accessed?

⬜ GitHub sets them, and they’re available in every step of a workflow.
⬜ You access them through the env context in the workflow file.
⬜ They’re defined in the workflow and can be overwritten.
⬜ Only steps that explicitly ask for them can use them.

A job that others depend on fails. What happens?

⬜ The workflow run is marked as failed.
⬜ All later jobs still run.
⬜ Only the dependent jobs are rerun.
⬜ The dependent jobs are skipped, and the other later jobs still run.

Which command is commonly used in a step to set an output that later steps can read?

⬜ debug
⬜ echo
⬜ export
⬜ set

What does timeout-minutes do on a step?

⬜ It sets the maximum number of minutes the step can run before its process is stopped.
⬜ It sets the maximum time the whole job can run.
⬜ It sets a time limit for each command inside the step.
⬜ It sets how long to wait for external events before going to the next step.

What is one benefit of triggering workflows manually?

⬜ You can test workflows in a controlled, deliberate way.
⬜ Workflows run automatically without anyone getting involved.
⬜ Workflows finish faster overall.
⬜ Runs are limited to specific branches only.

What is an advantage of running shell commands in job steps?

⬜ They give you the flexibility to run custom scripts and commands.
⬜ They let you trigger workflows manually.
⬜ They can only be used for debugging.
⬜ Shell commands can’t be used in workflows.

Which deployment protection rules can you configure on an environment? (select three)

⬜ Required reviewers before deployment
⬜ Preventing self-review of deployments
⬜ Restricting which branches can deploy to the environment
⬜ Enforcing a minimum code coverage

In Bash, how do you make an environment variable available to later steps in the same job?

⬜ Append it to the GITHUB_ENV file, for example echo "NAME=value" >> "$GITHUB_ENV".
⬜ Use the export command.
⬜ Set the variable in a separate configuration file.
⬜ Pass the variable to each step as an argument.

⬜ Review the workflow logs and documentation for configuration details.
⬜ Hard-code the values temporarily for testing.
⬜ Ignore the variables and focus on other parts of the code.
⬜ Rely only on external forums and ignore internal resources.

What does setting a default working directory for run commands do?

⬜ It sets the directory, such as where your scripts live, that run commands execute in.
⬜ It restricts scripts to specific directories on the runner.
⬜ It sets where script output is saved after it runs.
⬜ It isolates script execution to improve the workflow’s security.

What is a key benefit of using service containers in a workflow for testing databases and services?

⬜ Easy access to real or simulated external dependencies
⬜ Faster code compilation
⬜ Seamless integration with GitHub Pages
⬜ Automatic detection of code vulnerabilities

When you try to publish an action to GitHub Marketplace, the Publish checkbox is disabled. What do you need to do?

⬜ Accept the GitHub Marketplace Developer Agreement.
⬜ Update the action’s metadata file.
⬜ Change the repository’s workflow files.
⬜ Create a separate repository for the action.

Why is it useful for workflows to authenticate directly to a cloud provider that supports OpenID Connect?

⬜ It improves security by avoiding long-lived credentials stored as secrets.
⬜ It makes the workflow run faster.
⬜ It removes the need for a GitHub repository.
⬜ It allows deployment without any authentication.

What’s important to know before deleting an artifact?

⬜ A deleted artifact can’t be restored.
⬜ Deleted artifacts can be restored on request.
⬜ You don’t need write access to the repository.
⬜ Deleting artifacts doesn’t affect GitHub Actions storage.

How can a workflow status badge show only runs triggered by the push event?

⬜ Add ?event=push to the end of the badge URL.
⬜ Use the branch name as the event parameter.
⬜ Embed the badge in an HTML file with event-specific styling.
⬜ Change the event name to “push” in the workflow file.

In this job, how do you read the current matrix values?
jobs:
  example_matrix:
    strategy:
      matrix:
        version: [10, 12, 14]
        os: [ubuntu-latest, windows-latest]

⬜ Through the matrix context, as matrix.version and matrix.os
⬜ Through strategy.matrix.version and strategy.matrix.os
⬜ Directly, as version and os
⬜ With a context keyword in the job configuration

A workflow that should run on the check_suite event never runs when its workflow file exists only on a feature branch. Which statement best explains why?

⬜ check_suite only triggers a workflow if the workflow file exists on the default branch.
⬜ GitHub Actions doesn’t support any workflow runs from feature branches.
⬜ check_suite only triggers for check suites created on protected branches.
⬜ check_suite doesn’t depend on branches and should run from any branch.

Which configuration runs a workflow when a release is published?

⬜

on:
  release:
    types: [published]

⬜

on:
  release:
    when: [published]

⬜

on: published

⬜

on:
  release:
    event: [published]
Which are valid workflow names? (select two)

⬜ name: learn-github-actions
⬜ name: ${{ 'learn-github-actions' }}
⬜ name: ${{ learn-github-actions }}
⬜ name: ${{ "learn-github-actions" }}

This workflow is triggered in the myorg/my-dev-repo repository. What happens to the production-deploy job?
name: example-workflow
on: [push]
jobs:
  production-deploy:
    if: github.repository == 'myorg/my-prod-repo'
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v7
      - uses: actions/setup-node@v4
        with:
          node-version: '20'
      - run: npm install -g bats

⬜ The job is marked as skipped.
⬜ The job runs its three steps.
⬜ The job errors.
⬜ The job runs if the Node version is 20.

Looking at this workflow, which container registry does it publish to?
name: Create and publish a Docker image
on:
  push:
    branches: ['release']
env:
  REGISTRY: ghcr.io
  IMAGE_NAME: ${{ github.repository }}

jobs:
  build-and-push-image:
    runs-on: ubuntu-latest
    permissions:
      contents: read
      packages: write
    steps:
      - name: Checkout repository
        uses: actions/checkout@v7
      - name: Log in to the Container registry
        uses: docker/login-action@v3
        with:
          registry: ${{ env.REGISTRY }}
          username: ${{ github.actor }}
          password: ${{ secrets.GITHUB_TOKEN }}
      - name: Extract metadata (tags, labels) for Docker
        id: meta
        uses: docker/metadata-action@v5
        with:
          images: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}
      - name: Build and push Docker image
        uses: docker/build-push-action@v6
        with:
          context: .
          push: true
          tags: ${{ steps.meta.outputs.tags }}
          labels: ${{ steps.meta.outputs.labels }}

⬜ GitHub Container registry
⬜ Docker Hub
⬜ Artifactory
⬜ Amazon ECR

What is the GITHUB_ACTIONS variable for?

⬜ It’s always set to true when GitHub Actions is running the workflow.
⬜ It shows the status of the workflow file.
⬜ It’s a placeholder for the workflow file.
⬜ It holds the URL of the GitHub API.

What is the main purpose of organization-level secrets?

⬜ To share secrets across several repositories without duplicating them
⬜ To serve personal repositories only
⬜ To store non-sensitive information
⬜ To give access to repository owners only


Domain 2: Consume and troubleshoot workflows (15–20%)

Which extra steps does GitHub add to every job in a workflow run?

⬜ “Set up job” and “Complete job”
⬜ “Set up job” and “Tear down job”
⬜ None; every step has to be defined in the workflow file.
⬜ “Checkout” and “Post-job cleanup”

For a workflow triggered by pull_request, where can you see the run’s status? (select three)

⬜ On the pull request, before it’s merged
⬜ On the repository’s Actions tab
⬜ On the pull request’s Checks tab
⬜ On the repository’s Issues tab

Which status filter shows only failed workflow runs on the Actions tab?

⬜ failure
⬜ errored
⬜ failed
⬜ completed

Which API does GitHub Actions use to report statuses, results and logs for a workflow?

⬜ The Checks API
⬜ The Deployments API
⬜ The Statuses API
⬜ The Actions API

⬜ Use the default environment variables that point to those locations.
⬜ Hard-code the file paths so the path is always correct.
⬜ Use relative paths to reference the filesystem.
⬜ Never refer to the filesystem in a workflow.

A workflow run with twelve jobs finished with two jobs failing because of a temporary network outage. The outage is over, and you want to rerun only the two failed jobs, not the ten that passed. What should you do?

⬜ Choose Re-run failed jobs from the re-run menu on the workflow run page.
⬜ Push an empty commit so the whole workflow runs again.
⬜ Delete the workflow run so GitHub schedules a replacement.
⬜ Remove the successful jobs from the workflow file and start a new run.

A developer’s workflow saves artifacts produced by its build job. Where in the GitHub web interface can they download those artifacts?

⬜ In the Artifacts section of the workflow run
⬜ In the job details of the build job
⬜ On the pull request linked to the workflow run
⬜ In the repository’s Releases section

When you create a new workflow, GitHub suggests workflow templates for your repository. Which button do you click to use one of them?

⬜ Configure
⬜ Use
⬜ Install
⬜ Deploy

While troubleshooting a workflow, you want to write a debug message to the log. How do you do it?

⬜ echo "::debug::executing the setup script"
⬜ log ::warning "executing the setup script"
⬜ logs ::debug "executing the setup script"
⬜ You can’t write debug messages to the log.

Which context property gives you information about the event that triggered a workflow run?

⬜ github.event
⬜ github.job
⬜ github.repository
⬜ jobs.<job_id>.result

On GitHub-hosted runners, what does the “Set up job” step record? (select three)

⬜ The runner image
⬜ The operating system
⬜ The GITHUB_TOKEN permissions
⬜ A code vulnerability scan

Jess wants to download a set of workflow run logs from a public repository through the REST API. Which values identify the logs she wants?

⬜ owner, repo and run_id
⬜ owner, repo and job_id
⬜ owner, repo and an authentication token
⬜ repo, an authentication token and run_id

When this workflow is triggered, what does the step print for NAME?
name: Java CI with Maven

env:
  NAME: 'My Action'

on:
  push:
    branches: [ "main" ]

jobs:
  build:
    env:
      NAME: 'My Action 2'

    runs-on: ubuntu-latest

    steps:
      - name: Print name
        run: echo "$NAME"
        env:
          NAME: 'My Action 3'

⬜ My Action 3
⬜ My Action 2
⬜ My Action
⬜ The run fails because of a syntax error.

What level of repository access do you need to download workflow artifacts?

⬜ Read
⬜ Write
⬜ Admin
⬜ Owner

John is troubleshooting a failed run and wants to see the workflow file that run used. Which option in the run’s menu shows it?

⬜ View workflow file
⬜ Download log archive
⬜ View raw logs
⬜ Create status badge

An organization’s workflow template uses ${{ secrets.token }}. What must you set up before using a workflow created from it?

⬜ Create a secret named token that your repository can use.
⬜ Replace ${{ secrets.token }} with the token’s actual value.
⬜ Skip the secrets and rely on default values.
⬜ Edit the workflow file to remove the secret reference.

Steve wants to check that an action is trustworthy before using it in his project. Which steps help him verify it? (select three)

⬜ Review the action’s action.yml and code to make sure it does what it claims.
⬜ Check whether the action is listed in GitHub Marketplace.
⬜ Check whether the action’s creator is verified in GitHub Marketplace.
⬜ Check how many GitHub stars the action has.

Which are valid types of custom action on GitHub? (select three)

⬜ Docker container actions
⬜ JavaScript actions
⬜ Composite actions
⬜ Composable actions

Sam wants a workflow to run whenever someone pushes to any branch or creates a tag. How should Sam write the trigger?

⬜ on: [push, create]
⬜ on: {push, create}
⬜ on: [push, tag]
⬜ on: {push, tag}

Phil wants to list only workflow runs triggered by pull requests on his repository’s Actions tab. Which filter should he use?

⬜ Event
⬜ Status
⬜ Branch
⬜ Actor

What happens if the .github/workflows directory contains an invalid workflow file?

⬜ GitHub Actions creates a failed workflow run for every new commit.
⬜ GitHub Actions is turned off for the repository to prevent failed runs.
⬜ GitHub Actions moves the invalid file into a separate branch.
⬜ GitHub Actions fixes the syntax errors automatically.

Dan wants Drew’s opinion on one line in the logs of a recent run. What’s an efficient way to point Drew at that line?

⬜ Click the line number in the step’s log to get a link to that line and share the link.
⬜ Download the log archive and email it to Drew.
⬜ Copy the line into a new issue in the repository.
⬜ Take a screenshot of that part of the log and send it.

Which secret or variable do you set to true to turn on step debug logging?

⬜ ACTIONS_STEP_DEBUG
⬜ ACTIONS_WORKFLOW_DEBUG
⬜ ACTIONS_JOB_DEBUG
⬜ ACTIONS_RUNNER_DEBUG

Tony wants a step that prints the current repository’s name. Which step does that?

⬜

- name: Print Repository Information
  run: |
    echo "Current Repository: $GITHUB_REPOSITORY"

⬜

- name: Print Repository Information
  run: |
    echo "Current Repository: GITHUB_REPOSITORY"

⬜

- name: Print Repository Information
  run: |
    echo "Current Repository: $GITHUB_REPOSITORY"
  env:
    GITHUB_REPOSITORY: actions/code-examples

⬜

- name: Print Repository Information
  run: |
    echo "Current Repository: $my_repo"
  env:
    my_repo: pwd
By default, how long does GitHub keep workflow logs and artifacts?

⬜ 90 days
⬜ 24 hours
⬜ 1 year
⬜ Indefinitely

Tom’s workflow calls a service that’s currently down. What should he do so the workflow stops logging errors until the service is back?

⬜ Disable the workflow.
⬜ Delete the workflow file.
⬜ Pause the workflow.
⬜ Edit the workflow file to skip the failing step.

What are the benefits of organization workflow templates? (select three)

⬜ They save time.
⬜ They promote consistency.
⬜ They promote best practices.
⬜ They use AI.

Which version of actions/checkout does this workflow use?
name: CI

on:
  push:
    branches: [ "main" ]
  pull_request:
    branches: [ "main" ]
  workflow_dispatch:

jobs:
  build:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout

      - name: Run a one-line script
        run: echo Hello, world!

⬜ None; uses: actions/checkout without a ref is invalid.
⬜ The latest version of the action
⬜ The action’s default version
⬜ Version 3

How many required inputs does this action metadata declare?
inputs:
  num-servers:
    description: 'Number of Servers'
    required: false
    default: '3'
  server-cpu-count:
    description: 'CPU count of the Servers'
    required: true

⬜ 1
⬜ 2
⬜ 3
⬜ 0

Dani wants a workflow to run when someone comments on an issue in a repository. Which event should she use?

⬜ issue_comment
⬜ issues
⬜ comment
⬜ issues.comment

What can you see directly in the list of runs on the Actions tab? (select three)

⬜ Each run’s status
⬜ Each run’s branch
⬜ How long each run took
⬜ Each run’s configuration

Jeff is searching a failed run’s build logs for a particular step, but the search returns nothing. What could explain this? (select two)

⬜ He hasn’t expanded the steps, so their output isn’t included in the search.
⬜ The text he searched for is misspelled or isn’t in the logs.
⬜ He’s exceeded the search query limit for the run.
⬜ The logs have been archived and can’t be searched.

What level of repository access do you need to delete log files from workflow runs?

⬜ Write
⬜ Read
⬜ Admin
⬜ Owner

Setting ACTIONS_STEP_DEBUG to true turns on step debug logging. How can it be configured?

⬜ As a secret or a variable; if both are set, the secret wins.
⬜ Only as a secret.
⬜ Only as a variable.
⬜ As a secret or a variable; if both are set, the variable wins.

Which action downloads artifacts in a workflow?

⬜ actions/download-artifact
⬜ actions/upload-artifact
⬜ actions/download
⬜ actions/upload

When does GitHub Actions let you delete a workflow run? (select two)

⬜ When the run has completed
⬜ When the run is more than two weeks old
⬜ When the run is more than one week old
⬜ When the run is queued

Dave is creating a workflow template for his organization. Where must he store the workflow file and its metadata file?

⬜ In a workflow-templates directory in the organization’s .github repository
⬜ In a .github/workflow-templates directory
⬜ In a workflow-templates directory in the current repository
⬜ In a .github/org-templates directory

On an action’s GitHub Marketplace listing, a small checkmark badge appears next to the name of the action’s creator. What is this badge?

⬜ The verified creator badge
⬜ The approved usage badge
⬜ The security check badge
⬜ The status badge

Which action.yml keys indicate the type of action?

⬜ runs.using
⬜ runs.type
⬜ name
⬜ inputs


Domain 3: Author and maintain actions (15–20%)

What is the file name of the metadata file that defines an action’s inputs, outputs and runs configuration?

⬜ action.yml (or action.yaml)
⬜ workflow.yaml
⬜ config.yaml
⬜ requirements.yaml

You’ve built a GitHub Action that needs a specific Linux operating system and custom tools. Which type of action fits best?

⬜ A Docker container action
⬜ A JavaScript action
⬜ A composite action
⬜ None; actions can’t use customized operating systems and tools.

What does a composite action provide?

⬜ It combines several workflow steps into one reusable action.
⬜ It creates custom Docker containers for isolated execution.
⬜ It connects third-party APIs and services directly to workflows.
⬜ It automates deployments to cloud platforms such as AWS and Azure.

Which statements about JavaScript actions are true? (select three)

⬜ They run directly on the runner and use binaries already present there.
⬜ They can run on Linux, Windows and macOS runners.
⬜ The GitHub Actions toolkit can speed up their development.
⬜ You should bundle binaries with the action’s code to simplify the workflow.

You’re running a new Docker container action and get a “permission denied” error when it runs entrypoint.sh. How do you fix this?

⬜ Put sudo before entrypoint.sh in the Dockerfile’s ENTRYPOINT instruction.
⬜ Point the action’s configuration at a different entrypoint.sh script.
⬜ Make entrypoint.sh executable with chmod +x and commit the change before using the action.
⬜ Add USER root to the Dockerfile so the script runs as an administrator.

When you create a custom action, which files does it typically include, depending on the action type? (select three)

⬜ A JavaScript entry file, such as index.js, for a JavaScript action
⬜ action.yml or action.yaml for the action’s metadata
⬜ A Dockerfile for a Docker container action that builds its own image
⬜ A script.py file for a Python action

You’re building a custom action that has to pass data to later steps in a workflow. Which metadata key should you use?

⬜ outputs
⬜ environment
⬜ runs
⬜ description

How do you make an input available inside the container of a Docker container action?

⬜ Pass the input with the args keyword in the action’s metadata file.
⬜ Define the input as a command-line argument when you run the container yourself.
⬜ Do nothing; the environment variable is always available inside the container automatically.
⬜ Read process.env.INPUT_<VARIABLE_NAME> in the action’s code.

You’ve written a new GitHub Action and want to share it with the wider community. Where should you publish it?

⬜ GitHub Marketplace
⬜ A private repository
⬜ A public repository
⬜ A personal blog or website

How does GitHub let runners download actions from internal or private repositories while keeping access controlled?

⬜ It creates a scoped installation token with read access to the repository that expires after one hour.
⬜ It gives direct access to the repository for the length of the workflow run.
⬜ It asks users to sign in with their GitHub credentials every time an action is downloaded.
⬜ It generates a personal access token with read access to the repository that’s valid for one hour.

You’re developing a custom action for your organization’s CI/CD pipeline and deciding how to version it. Which practice follows industry standards and keeps versioning simple?

⬜ Use semantic versioning for release tags to communicate changes clearly and preserve compatibility.
⬜ Skip versioning and identify the action’s state by Git commit hashes only.
⬜ Name versions after the release date and time.
⬜ Give each release an arbitrary unique version number.

What is a good way to set up a release strategy for a GitHub Action?

⬜ Make every update available immediately, without documentation.
⬜ Update the action from time to time without any versioning.
⬜ Keep a clear changelog but don’t version the updates.
⬜ Define a release-management strategy and document major versions, critical fixes and security patches.

What is a requirement for publishing an action to GitHub Marketplace?

⬜ The action must be in a public repository.
⬜ Each repository must contain several actions.
⬜ The action’s metadata file must be in a subdirectory of the repository.
⬜ The name in the action’s metadata file must match an existing Marketplace category.

What do you need to provide when you draft a release to publish an action to GitHub Marketplace?

⬜ A primary category from the category menu, so people can find the action
⬜ A metadata file name that matches an existing Marketplace category
⬜ Nothing extra, because publishing a release doesn’t require two-factor authentication
⬜ A blank release title, so one can be generated automatically

Your organization mainly runs Windows and wants to start using Docker for build and test jobs. What must be in place before you can use Docker container actions?

⬜ Runners with a Linux operating system and Docker installed
⬜ Docker installed and configured on developers’ local machines
⬜ Docker installed on the Windows runners
⬜ All repositories switched to Windows as their main environment

You’re creating a JavaScript action, but this part of its action.yml file is wrong. What’s the problem?
runs:
  using: 'node24'
  steps: 'main.js'

⬜ JavaScript actions don’t use steps; use main to point to the entry file instead.
⬜ JavaScript actions don’t use action.yml; they need an index.js file instead.
⬜ JavaScript actions must use node12, and this code uses node24.
⬜ JavaScript actions don’t need Node.js, so this action will fail.

The workflow logs don’t give enough detail to diagnose a problem with your new JavaScript action. What should you do next?

⬜ Turn on debug logging to make the job’s logs more detailed.
⬜ Review the JavaScript action’s code for errors or misconfiguration.
⬜ Use the GitHub Actions API to get more diagnostic information about the failed job.
⬜ Convert the action to a Docker container action for more detailed logging.

You committed the files for a Docker container action, but the action fails to run. The repository looks like this. What’s the likely problem?
prd-app-repo/
  |--dockerfile
  |--action.yml
  |--script.sh
  |--README

⬜ File names are case-sensitive, so dockerfile should be named Dockerfile.
⬜ Docker container actions don’t use action.yml, which causes the failure.
⬜ The README file should be outside the action’s directory.
⬜ script.sh isn’t mentioned in the README file.

You’re creating a custom action and a workflow that uses it. Which components are required? (select three)

⬜ A workflow file in YAML
⬜ An action metadata file
⬜ Trigger events that start the workflow
⬜ A directory for storing artifacts
⬜ Environment variables to configure the workflow environment

How do you publish an action you’ve built to GitHub Marketplace?

⬜ Tag it as a new release and publish that release.
⬜ Create a new branch in your repository.
⬜ Merge a pull request from another user.
⬜ Rename the repository to match an existing GitHub feature.

⬜ Move the major version tag to point at the current release’s Git ref.
⬜ Introduce a new major version tag for changes that will break existing workflows.
⬜ Release new major versions with a beta tag to show their status.
⬜ Create and validate releases directly on the main branch before creating the release tag.
⬜ Use non-semantic version names for release tags to make them clearer.

How do JavaScript actions differ from typical Node.js projects in how they’re developed and distributed?

⬜ They commit their dependent packages, or a bundled build, alongside the code and can be published as tagged releases to GitHub Marketplace.
⬜ They don’t support dependent packages or tagged releases.
⬜ They don’t need end-to-end testing because they’re simple.
⬜ They can only use GitHub’s APIs, not third-party APIs.

What is a main reason to host a public GitHub Action in its own separate repository?

⬜ It makes it easier for developers to extend the action and fix its issues.
⬜ It makes the action more complex to manage.
⬜ It limits the action’s visibility to the repository that hosts it.
⬜ It reduces the need for version control.

As you prepare to distribute your custom action, what should you do to make it easy to find and useful for potential users?

⬜ Give a clear description of what the action does and choose the most relevant category.
⬜ Give a brief description and choose many categories to maximize exposure.
⬜ Keep the description minimal so users explore and experiment.
⬜ List every feature in the description to attract a wider audience.

Your project needs a custom action, but because the project is sensitive, the action can’t be public. How can you still use it?

⬜ Allow GitHub Actions workflows in your private repository to access another private repository that contains the action.
⬜ Turn the action into a Docker container and store it in a private registry.
⬜ Host the action in a separate public repository and grant access to specific users or organizations.
⬜ Copy the action’s code into your project repository and include it in your workflow files.

An action fails unexpectedly during a run. How did GitHub decide, from the action’s exit code, that it failed?

⬜ The action returned a nonzero exit code, which GitHub treats as failure and uses to set the check run status.
⬜ GitHub treats a nonzero exit code as success, so the workflow continues uninterrupted.
⬜ GitHub treats every exit code as failure, ending the run.
⬜ GitHub ignores exit codes and relies on manual review to decide success or failure.

Instead of calling toolkit code to create an error annotation, what can you use to send the runner a command that creates the same annotation?

⬜ Workflow commands, which correspond to actions/toolkit functions
⬜ The set-env command
⬜ Python scripts that create the error messages
⬜ Environment variables prefixed with RUNNER_

What syntax do you use to write an action metadata file?

⬜ YAML
⬜ JSON
⬜ JavaScript
⬜ Python

How can you see detailed logs to troubleshoot a Docker container action?

⬜ Check the GitHub Actions logs for details of how the action ran.
⬜ Read the action’s README for troubleshooting tips.
⬜ Run docker logs to view the action’s logs.
⬜ Run git log to view the action’s commit history.

⬜ Under .github/actions, with a separate subdirectory for each action
⬜ In a single actions directory holding all the action files together
⬜ Under src, with a subdirectory per language
⬜ Under workflows, with a workflow file defining each action

A workflow_dispatch workflow declares an input with required: true. What happens when someone runs it manually?

⬜ GitHub prompts the user to enter the inputs before the workflow runs.
⬜ The workflow returns an error if inputs aren’t given.
⬜ The inputs are filled in automatically from the previous run.
⬜ The workflow runs without asking for inputs.

What are actions in GitHub workflows?

⬜ Individual, customizable tasks that do specific jobs within a workflow
⬜ Automated scripts that run code without any user input
⬜ Predefined workflows that GitHub provides for common tasks
⬜ Plugins for popular IDEs such as Visual Studio Code

Why should an action’s repository contain only the metadata file, code and files the action needs?

⬜ So the action can be tagged, released and packaged as a single unit
⬜ To meet GitHub’s review process
⬜ To make the repository smaller
⬜ To make the repository more visible on GitHub

What is the main idea behind the automated release-management strategy GitHub describes for actions?

⬜ Commit dependencies only to tagged release commits, and run builds as part of the release, for better security.
⬜ Commit dependencies to every branch to speed up releases.
⬜ Discourage users from referencing named tags or SHAs.
⬜ Encourage committing dependencies directly to the main branch.

⬜ Write a thorough README.md with a description, inputs and outputs, secrets, environment variables and usage examples.
⬜ Write a full troubleshooting guide for possible issues.
⬜ Make a detailed list of every feature.
⬜ Build an interactive tutorial for setup and use.

You’ve built an action that automates deployments for your organization’s web apps. What might lead you to publish it in a public repository?

⬜ You want the wider GitHub community to collaborate on it and improve it over time.
⬜ You want to raise your organization’s brand profile in deployment automation.
⬜ You need it to work with other public repositories and workflows across organizations.
⬜ You want only authorized users in your organization to use it.

You want to publish your new action to GitHub Marketplace. Which requirements must be met for it to be published immediately? (select five)

⬜ The action is in a public repository.
⬜ The action’s metadata file is in the repository’s root directory.
⬜ The name in the metadata file is unique.
⬜ The repository contains more than one action.
⬜ The name doesn’t match an existing Marketplace category.
⬜ You’ve accepted the terms of service for publishing actions in Marketplace.

You printed a debug message with a workflow command, but you can’t find it in the logs. What’s the likely reason?

⬜ Debug messages aren’t shown in the logs unless debug logging is turned on.
⬜ The message was printed in the wrong step.
⬜ The workflow wasn’t triggered by a relevant event.
⬜ The message used the wrong syntax.

What value should replace the placeholder so that the action’s output returns the step’s random number?
runs:
  using: "composite"
  steps:
    - id: random-number-generator
      run: echo "random-id=$(echo $RANDOM)" >> $GITHUB_OUTPUT
      shell: bash
outputs:
  random-number:
    description: "Random number"
    value: ${{ <what-should-go-here> }}

⬜ steps.random-number-generator.outputs.random-id
⬜ outputs.random-id
⬜ random-number-generator.outputs.random-id
⬜ random-id

What advantage do JavaScript actions have over Docker container actions?

⬜ They run directly on the runner, which keeps the action simpler and makes it run faster.
⬜ Docker container actions give better isolation and security than JavaScript actions.
⬜ JavaScript actions integrate more easily with third-party APIs.
⬜ Docker container actions run consistently across operating systems.

⬜ Check the run logs to see which step failed, then review that step’s log output.
⬜ Review the action’s code for syntax errors and debugging statements.
⬜ Run the action locally with a GitHub Actions CLI tool.
⬜ Switch to Docker container actions for stability.

How can you check which environment variables are passed into your own Docker container action?

⬜ Run the env command inside the action’s container to print them.
⬜ Run docker inspect on the action from your local machine.
⬜ Read the environment variables section of the action’s YAML file.
⬜ Look for a breakdown of every variable’s value in the GitHub Actions logs.

What advantage do composite actions with run steps offer?

⬜ They let you run shell scripts directly, without extra setup.
⬜ They provide a graphical interface for configuration.
⬜ They integrate third-party APIs without any code.
⬜ They generate documentation from the included scripts automatically.

What are the steps to publish your action to GitHub Marketplace?

⬜ Put the metadata file at the repository root, draft a release, select Publish this Action to the GitHub Marketplace, choose categories, set a version tag and publish the release.
⬜ Tag a new release, push it, draft a release, select Publish this Action to the GitHub Marketplace and set a version tag.
⬜ Submit the metadata file to GitHub for review, choose categories, set a version tag, draft a release and publish it.
⬜ Merge the metadata file into the main branch, draft a release, select Publish this Action to the GitHub Marketplace and choose categories.

How does GitHub use an action’s metadata on its Marketplace page?

⬜ It uses the metadata to show key information and details about the action.
⬜ It uses the metadata to categorize actions by function.
⬜ It uses the metadata to generate usage documentation.
⬜ It shows the metadata as a separate web page for each action.

What should users generally do when referencing a GitHub Action in their workflows?

⬜ Reference a major version, and pin to a more specific version only if problems come up.
⬜ Point directly at the latest commit’s SHA to stay compatible.
⬜ Always reference the action’s default branch to get the latest code.
⬜ Configure the workflow to update to the latest version automatically.

Which belong in a thorough README.md for a custom action? (select five)

⬜ A detailed description of what the action does
⬜ Required input and output arguments
⬜ Optional input and output arguments
⬜ Secrets the action uses
⬜ Environment variables the action uses
⬜ An interactive tutorial
⬜ A troubleshooting guide for common issues

Your workflow logs are getting cluttered during a complex run, and you want to make them easier to read. Which workflow command helps?

⬜ group
⬜ echo
⬜ add-mask
⬜ stop-commands

When an action input is given in a workflow or uses a default value, how does GitHub name the matching environment variable?

⬜ It converts the input name to uppercase and replaces spaces with _ characters.
⬜ It keeps the input name unchanged but replaces spaces with - characters.
⬜ It joins the name with INPUT_ and removes spaces.
⬜ It converts the input name to lowercase and replaces spaces with _ characters.


Domain 4: Manage GitHub Actions for the enterprise (20–25%)

A configuration variable called DEPLOY_REGION is defined at the organization level, the repository level and in the repository’s production environment, each with a different value. A job sets environment: production and prints ${{ vars.DEPLOY_REGION }}. Which value is printed?

⬜ The value defined in the production environment
⬜ The value defined at the repository level
⬜ The value defined at the organization level
⬜ An empty string, because the workflow can’t resolve the conflict

Your organization uses GitHub Actions on GitHub Enterprise Cloud and wants automation to be reused and maintained consistently when people create new workflows in its repositories. Which feature should it use?

⬜ Workflow templates
⬜ Contribution guidelines
⬜ Naming conventions
⬜ The GitHub wiki

You want to restrict public actions and reusable workflows so that people can only use actions and reusable workflows from inside your enterprise. Where do you set this?

⬜ In the enterprise’s Policies section, under Actions
⬜ In a shared repository’s settings, using Disable GitHub Actions
⬜ In the policies section of the GitHub Codespaces page
⬜ In a personal access token’s token policies

Your self-hosted runner sits on a network that needs a proxy server to reach the internet. Which environment variable should you set on the runner so it can communicate with GitHub?

⬜ https_proxy
⬜ proxy_server
⬜ network_proxy
⬜ outbound

You’ve created a secret called api_key for a deployment workflow. Which syntax correctly passes the secret to a step as an environment variable?

⬜

steps:
  - shell: bash
    env:
      ENV_API_KEY: ${{ secrets.api_key }}
    run: |
      ./app_install.sh

⬜

steps:
  - shell: bash
    with:
      ENV_API_KEY: ${{ api_key }}
    run: |
      ./app_install.sh

⬜

steps:
  - shell: bash
    env:
      ENV_API_KEY: ${{ secrets.environment.api_key }}
    run: |
      ./app_install.sh

⬜

steps:
  - shell: bash
    with:
      ENV_API_KEY = api_key
    run: |
      ./app_install.sh
Your organization uses many custom actions and scripts in GitHub Actions workflows across projects. Which approach to naming files and folders would help most with collaboration and managing these components?

⬜ Set and enforce an organization-wide naming convention that shows each component’s type, purpose and version.
⬜ Use random names or abbreviations to keep file names short.
⬜ Let each team set its own naming convention for reusable components.
⬜ Follow existing platform or language conventions without organization-specific guidelines.

Your operations team wants to use GitHub-hosted runners for CI, but the security team insists on an IP address allowlist. Why might this be a burden for the operations team?

⬜ GitHub-hosted runner IP addresses change, and keeping the allowlist current each week is time-consuming, error-prone and adds admin overhead.
⬜ Coordinating with the security team might delay setting up and scaling CI workflows.
⬜ GitHub doesn’t publish the IP addresses used by GitHub Actions.
⬜ Making services without static IP addresses compatible could be difficult and limit workflow flexibility.

Your team pays for its own infrastructure under a chargeback model and wants to stop development workflows from using the runners it pays for. Which GitHub Actions feature helps?

⬜ Runner groups
⬜ Runner environments
⬜ Runner sets
⬜ Runner labels

You use ephemeral self-hosted runners in containers. They keep updating themselves every time a new runner version comes out, which causes disruption. What can you do?

⬜ Turn off automatic updates and update the runner version in the container image yourself.
⬜ Turn on automatic updates so the runner software stays current.
⬜ Schedule updates with GitHub’s built-in update scheduler.
⬜ Configure workflows to handle runner software updates as needed.

What is the main purpose of custom labels on self-hosted runners?

⬜ To route jobs to specific kinds of self-hosted runners
⬜ To make workflows easier to read
⬜ To improve runner security
⬜ To give workflow jobs descriptive names

⬜ Create a dedicated repository to store and manage all the reusable workflows.
⬜ Reuse workflows directly from individual project repositories.
⬜ Use workflow_call in workflows to call reusable workflows from other repositories.
⬜ Version reusable workflows with branches and tags.

Your organization uses IP allowlists to protect internal resources that GitHub Actions workflows access. Most workflows run on GitHub-hosted runners and need both Windows and Linux. How can you meet the security requirement while keeping workflows reliable?

⬜ Use larger runners with static IP address ranges and add those ranges to the allowlist.
⬜ Run self-hosted runners on-premises with specific IPs added to the allowlist.
⬜ Allowlist the entire Azure IP address range, because Windows and Ubuntu hosted runners run in Azure.
⬜ Create separate workflows that use only self-hosted runners and bypass the allowlists entirely.

You need to store a sensitive database password for your organization’s workflows. As an organization owner, how do you create a secret that only certain repositories can use?

⬜ Create an organization-level secret and set its access policy to the specific repositories that need it.
⬜ Hard-code the password in the workflows for easy access.
⬜ Create a repository secret in the main project repository and share it manually with the others.
⬜ Make the main repository public and use private workflow permissions for individual runs.

Which runner option is most cost-effective and needs the least management?

⬜ GitHub-hosted runners provided by GitHub
⬜ Self-hosted runners on virtual machines your organization manages
⬜ Self-hosted runners on physical servers your organization maintains
⬜ Runners hosted by a third-party cloud provider

A new self-hosted runner was registered with your organization, but it doesn’t appear in your team’s runner group. Why can’t you use it?

⬜ New runners are placed in the default group automatically, so it has to be moved to your team’s group.
⬜ The runner is still initializing and configuring itself.
⬜ Your team hasn’t been given permission to the runner group.
⬜ A network issue is stopping the runner from showing up in the group.

How do custom labels decide whether a self-hosted runner can take a job?

⬜ Labels are cumulative, so the runner must have every label the job asks for.
⬜ Labels work independently, so any matching label is enough.
⬜ Labels are mutually exclusive, so only one matching label is needed.
⬜ Labels are assigned automatically from the runner’s characteristics.

⬜ Encrypt the file with GPG, commit the encrypted file, and store the decryption passphrase as a secret.
⬜ Store the large secret directly as a repository secret.
⬜ You can’t use secrets larger than 48 KB at all.
⬜ Don’t store large secrets, for security reasons.

When setting company standards for GitHub Actions workflows in a large organization, which things are essential to document? (select three)

⬜ Which repositories hold the different workflow components
⬜ Naming conventions for files and folders
⬜ Plans for ongoing maintenance and versioning of workflows
⬜ Instructions for setting up and integrating each individual workflow

Your organization needs a runner for several workflows with CPU-intensive, high-memory jobs that also reach sensitive internal resources. Which runner type fits best?

⬜ A self-hosted runner on dedicated hardware
⬜ A standard GitHub-hosted runner
⬜ A self-hosted runner on a VM in your cloud infrastructure
⬜ A larger GitHub-hosted runner

You’re monitoring your organization’s self-hosted runners in the GitHub UI. Which statuses can a runner show? (select three)

⬜ Idle
⬜ Active
⬜ Offline
⬜ Overloaded

⬜ An owner has restricted actions and reusable workflows to ones from your organization.
⬜ The organization hasn’t been added to the public GitHub repository.
⬜ The default GITHUB_TOKEN can’t read these actions.
⬜ The users are running the actions on self-hosted runners.

Your team deploys the organization’s flagship application, and deployment needs custom software tools. What type of runner is ideal?

⬜ Self-hosted runners on virtual machines your organization manages
⬜ GitHub-hosted runners provided by GitHub
⬜ Runners hosted by a third-party cloud provider
⬜ Larger GitHub-hosted runners with only their preinstalled tools

Your team is troubleshooting a self-hosted runner’s connectivity. Which option checks that the runner can reach all the GitHub network services it needs?

⬜ --check
⬜ --diag
⬜ --validate-network
⬜ --verify-connection

You’re working in a colleague’s personal repository and can’t add a secret for a workflow. What do you need to do?

⬜ Ask your colleague, who owns the repository, to add the secret.
⬜ Ask GitHub Support to give you permission to add secrets.
⬜ Fork the repository and add the secret to your fork.
⬜ Open a pull request that adds the secret, for your colleague to merge.

When choosing runners for support workloads, what’s the key factor to consider about supported operating systems?

⬜ Whether the operating system works with the tools and dependencies the tasks need
⬜ The cost of licensing the operating system
⬜ How popular the operating system is with the team
⬜ How often the vendor releases updates

As an enterprise owner, you want to restrict GitHub Actions across your organizations while still allowing the essential workflows. Which configuration does this?

⬜ Enforce a policy that allows only local actions and reusable workflows.
⬜ Disable GitHub Actions for every organization in the enterprise.
⬜ Allow all Marketplace actions but restrict workflows to certain organizations and repositories.
⬜ Require two-factor authentication for everyone who runs workflows.

A colleague is deciding between GitHub-hosted and self-hosted runners. Which points best explain the difference? (select three)

⬜ Self-hosted runners often run in a persistent environment and can keep custom configuration, software and caches between jobs.
⬜ Self-hosted runners can reach resources inside your private network, unlike standard GitHub-hosted runners.
⬜ GitHub-hosted runners are ephemeral, so each job usually gets a fresh virtual machine.
⬜ Self-hosted runners need less technical expertise to set up and manage.
⬜ GitHub-hosted runners give complete control to install and configure any software.

Daniel is deciding whether to store a sensitive API key as an organization secret or an environment secret. Which factors should he consider? (select three)

⬜ How many repositories need the API key
⬜ How often the API key has to be updated
⬜ The level of access control needed for the different teams that use the key
⬜ Whether workflows need individual approval before they can access the key

What are the benefits of reusing workflows across an organization? (select four)

⬜ Avoids duplication
⬜ Makes workflows easier to maintain
⬜ Lets you build on others’ work
⬜ Promotes best practices across the organization
⬜ Removes all security threats to the application
⬜ Lets you create a workflow with test, staging and QA jobs

The IT governance team needs GitHub Actions policies that ensure compliance and security. What is the most effective approach?

⬜ Provide organization-wide templates of approved workflows with security measures built in.
⬜ Run regular training on creating secure, compliant workflows.
⬜ Require code review for every workflow change.
⬜ Use environment variables to enforce custom policies across repositories.

At which levels can you create an encrypted secret in a GitHub organization? (select three)

⬜ Organization
⬜ Environment
⬜ Repository
⬜ Workflow

What are the downsides of using self-hosted runners? (select three)

⬜ The overhead of maintaining and updating the runner environment
⬜ Managing the security risks of self-hosted infrastructure
⬜ The need for stable network connectivity for the runner to work
⬜ No access to GitHub’s built-in features and updates
⬜ Less scalability than GitHub-hosted runners

What network requirement must self-hosted runners meet to connect to GitHub?

⬜ Allow outbound connections to GitHub hosts, which the runner uses for long polling.
⬜ Access to all of GitHub’s public APIs and services
⬜ A high-speed internet connection to minimize latency
⬜ A proxy for all outbound connections to GitHub


Domain 5: Secure and optimize automation (10–15%)

Your deployment workflow authenticates to a cloud provider with long-lived access keys stored as repository secrets. You want to switch to OpenID Connect (OIDC) so the workflow exchanges a short-lived token instead. Which permission must the workflow grant to request the OIDC token?

⬜ id-token: write
⬜ contents: write
⬜ deployments: write
⬜ actions: read

⬜ Reference actions by their full commit SHA.
⬜ Use branch names instead of tags.
⬜ Use shortened commit SHAs to make tracking easier.
⬜ Keep using tags, but avoid deleting or moving them.

When might it make sense to use both GitHub-hosted and self-hosted runners in a workflow?

⬜ When some jobs are resource-intensive
⬜ When you want the highest level of security
⬜ When working on a personal project with few dependencies
⬜ When running short-lived, stateless jobs in isolation

Why should you avoid passing secrets between processes on the command line?

⬜ Command lines can be visible to other users or captured by security audit events.
⬜ It’s actually the recommended practice.
⬜ Command-line processes can’t be captured by security audit events.
⬜ Command-line processes redact any secrets they handle automatically.

What is the GITHUB_TOKEN secret used for in a workflow?

⬜ Authenticating on behalf of GitHub Actions
⬜ Storing sensitive values such as API keys
⬜ Triggering workflow runs manually
⬜ Configuring repository settings

What is the main reason to cache dependencies in a GitHub Actions workflow?

⬜ To reduce network use, run time and cost
⬜ To make the workflow YAML smaller
⬜ To remove the need for GitHub-hosted runners
⬜ To create workflows automatically

A job is waiting for an environment’s required reviewers. What happens if nobody approves it within 30 days?

⬜ The job fails automatically.
⬜ The job starts automatically without approval.
⬜ The job is held indefinitely until someone approves it.
⬜ The job stays in the “Waiting” status until it’s approved.

April is auditing the operations team and sees many workflows using secrets for deployment and testing. She worries the secrets might appear in logs. What can you tell her?

⬜ GitHub automatically redacts secrets printed to workflow logs, replacing them with placeholders.
⬜ GitHub encrypts secrets before printing them to workflow logs.
⬜ GitHub asks users to confirm before printing secrets to logs.
⬜ GitHub doesn’t allow workflow logs to be printed at all.

When does the GITHUB_TOKEN expire?

⬜ When the job finishes, or when it reaches its maximum lifetime (6 hours on GitHub-hosted runners, up to 24 hours on self-hosted runners)
⬜ After 12 hours, whether or not the job has finished
⬜ After 48 hours, whatever happens in the workflow
⬜ It never expires.

How do workflow jobs that reference an environment with protection rules behave?

⬜ They don’t start until all of the environment’s protection rules pass.
⬜ They start straight away, regardless of the protection rules.
⬜ They start as soon as some of the protection rules pass.
⬜ They never start if the environment has protection rules.

In a workflow that needs a deployment review, what happens if the reviewer rejects the job?

⬜ The workflow fails.
⬜ The job is resubmitted for review automatically.
⬜ The workflow continues as normal.
⬜ The job is put on hold until further notice.




Take all 207 questions as a timed online practice exam, free:-