GitHub Administration (GH-100) Exam Questions
Page content
Comprehensive list of Free GitHub Administration (GH-100) exam questions, grouped by the official exam skill domains, curated for cracking the exam with confidence.
Disclaimer: GitHub, GitHub Actions and GitHub Copilot are trademarks of GitHub, Inc. These exam questions are neither endorsed by nor affiliated with GitHub or Microsoft. These are not the official GitHub Administration exam questions/dumps. These are original questions written from the GitHub documentation. They cover all 5 skill domains of the GitHub Administration (GH-100) exam, following the skills outline updated in July 2026, and once you go through these questions and their concepts, you are more than ready to crack the exam in first attempt.
Free Online Practice Exam
Take all 200 questions as a timed online practice exam, free:-
Overview
- This is an intermediate-level certification for administrators of GitHub Enterprise Cloud and GitHub Enterprise Server: identity and access (enterprise managed users, SAML SSO, SCIM, roles and enterprise teams), support and licensing, security and compliance (policies, rulesets, audit logs, secret scanning, code scanning, Dependabot, tokens and apps), GitHub Actions administration (policies, runners, networking, secrets) and usage monitoring and cost optimization.
- It suits enterprise and organization owners, platform administrators, DevOps engineers and technology managers who run GitHub for a company.
- Exam code is GH-100. The study guide calls it GitHub Enterprise Administrator. The exam is delivered through Microsoft Learn (Pearson VUE), online proctored or at a test center, in English only. The price depends on your country or region.
- Exam duration is 100 minutes. GitHub doesn’t publish a fixed question count; questions are multiple choice and multiple select, mostly scenario based, and may cover commonly used preview features.
- The passing score is 700 (on a scale of 1–1000).
- The exam covers 5 skill domains (see the weighting table below), following the skills measured as of July 2026. Product names have changed recently (GitHub Secret Protection and GitHub Code Security replace GitHub Advanced Security; usage-based licensing; enterprise teams), so check the docs for the latest behavior.
- Official certification page, GH-100 study guide and GitHub Enterprise Cloud documentation for more details.
200 Practice Questions
| # | Domain | Weight | Questions below |
|---|---|---|---|
| 1 | Manage GitHub identities and access | 15–20% | 38 |
| 2 | Administer GitHub Enterprise environment | 10–15% | 27 |
| 3 | Implement secure software development and compliance | 25–30% | 59 |
| 4 | Manage GitHub Actions | 20–25% | 49 |
| 5 | Monitor and optimize GitHub usage | 10–15% | 27 |
Domain 1: Manage GitHub identities and access (15–20%)
A company wants its identity provider to create, update and remove its developers’ GitHub accounts, and wants those developers to sign in only through that IdP. Which GitHub Enterprise Cloud option provides this?
⬜ An enterprise with Enterprise Managed Users
⬜ An enterprise with personal accounts and organization-level SAML SSO
⬜ An enterprise with personal accounts and enterprise-level SAML SSO
⬜ An enterprise with personal accounts and two-factor authentication required
Which identity providers are GitHub partner IdPs for Enterprise Managed Users? (select three)
⬜ Microsoft Entra ID
⬜ Okta
⬜ PingFederate
⬜ OneLogin
⬜ Shibboleth
An enterprise with managed users is planning its IdP setup. Which combination does GitHub explicitly not support?
⬜ Okta for authentication with Microsoft Entra ID for SCIM provisioning, or the other way round
⬜ Microsoft Entra ID for both OIDC authentication and SCIM provisioning
⬜ Okta for both SAML authentication and SCIM provisioning
⬜ PingFederate for both SAML authentication and SCIM provisioning
An enterprise with managed users wants GitHub to honor its identity provider’s Conditional Access Policy (CAP). What does this require?
⬜ OIDC authentication with Microsoft Entra ID
⬜ SAML authentication with any partner IdP
⬜ SAML authentication with Okta
⬜ OIDC authentication with PingFederate
An enterprise uses OIDC with Microsoft Entra ID and relies on GitHub’s support for its Conditional Access Policy. Which statements about this support are correct? (select two)
⬜ GitHub enforces the policy’s IP conditions, including for each personal access token or SSH key authentication tied to a user.
⬜ The IdP’s IP conditions can be used instead of GitHub’s own IP allow list.
⬜ GitHub enforces the policy’s device compliance conditions on every request.
⬜ Deploy keys are blocked whenever the caller’s IP doesn’t meet the policy.
⬜ GitHub Apps acting as their installation are blocked when their IP isn’t allowed by the policy.
Which actions are blocked for managed user accounts in an enterprise with Enterprise Managed Users? (select three)
⬜ Creating or commenting on gists
⬜ Forking repositories from outside the enterprise
⬜ Signing up for GitHub Copilot Pro or Copilot Free
⬜ Viewing public repositories on GitHub.com
⬜ Being added as a collaborator to an organization-owned repository in the enterprise
⬜ Contributing to internal repositories in the enterprise
A new enterprise with managed users has just been created. What is the username of the setup user?
⬜ The enterprise’s shortcode followed by _admin, for example fabrikam_admin
⬜ The email address of the person who requested the trial
⬜ admin followed by the enterprise’s shortcode, for example admin_fabrikam
⬜ The first user that SCIM provisions from the IdP
While setting up Enterprise Managed Users, an administrator signs in as the setup user to create the personal access token used for SCIM provisioning. How should that token be configured?
⬜ With the scim:enterprise scope and no expiration
⬜ With the admin:org scope and a 30-day expiration
⬜ As a fine-grained token limited to the enterprise’s organizations
⬜ With the repo scope and a 90-day expiration
When a managed user is deprovisioned through SCIM, what happens to their account?
⬜ It’s suspended, and its username is replaced with a hash followed by the enterprise shortcode.
⬜ It’s deleted immediately, together with all comments the user wrote.
⬜ It’s converted into a personal account that the user can keep.
⬜ It stays active until an enterprise owner deletes it manually.
By default, how long can a member work in a SAML SSO-protected organization before GitHub sends them back to the IdP to re-authenticate?
⬜ 24 hours, unless the IdP specifies a different period
⬜ 8 hours, regardless of the IdP’s settings
⬜ 7 days, unless the organization owner changes it
⬜ 30 days, the lifetime of the GitHub session cookie
A public repository belongs to an organization that enforces SAML SSO. Which actions can a member take without an active SSO session? (select two)
⬜ Fork the repository
⬜ Clone the repository with Git
⬜ View the repository’s issues
⬜ View the repository’s pull requests
⬜ Comment on a pull request in the repository
A member of a SAML SSO-protected organization gets an error when using a personal access token (classic) to call the API for the organization’s repositories. What should they do?
⬜ Authorize the token for use with the organization.
⬜ Sign in to the IdP again, because API calls use the browser SSO session.
⬜ Replace the token with their GitHub password.
⬜ Ask an owner to turn off SAML enforcement for API access.
Which identity providers does GitHub officially support and test for organization SAML SSO? (select three)
⬜ Active Directory Federation Services (AD FS)
⬜ OneLogin
⬜ Shibboleth
⬜ Auth0
⬜ Google Workspace
An organization uses SAML SSO with personal accounts but hasn’t implemented SCIM. A developer leaves the company and is disabled in the IdP. What happens to their organization membership?
⬜ Nothing automatic; an owner must also remove them from the organization on GitHub.
⬜ GitHub removes them from the organization at the end of their SAML session.
⬜ GitHub suspends their personal account.
⬜ GitHub converts them to an outside collaborator.
An organization set up SCIM provisioning with its IdP using an owner’s account. Months later SCIM stops working. Which documented cause is most likely?
⬜ The user who last authorized the SCIM OAuth app left or was removed from the organization.
⬜ The organization’s SAML session lifetime expired.
⬜ The organization exceeded the maximum number of SCIM-provisioned users.
⬜ An enterprise owner turned on the IP allow list.
Which statements about SCIM for organizations that use personal accounts are correct? (select two)
⬜ It can’t be used for an enterprise account or for organizations with managed users.
⬜ The IdP must use matching NameID and userName values for each user.
⬜ It can be used without SAML SSO.
⬜ It creates and deletes users’ personal accounts.
⬜ It works only with PingFederate.
An organization owner connects a team to an IdP group with team synchronization. Which statements are correct? (select three)
⬜ A team can be connected to up to five IdP groups.
⬜ IdP groups with more than 5,000 members aren’t supported.
⬜ Team membership can no longer be managed on GitHub or with the API.
⬜ Parent teams can be synchronized with IdP groups.
⬜ Synchronized team members can still be given the team maintainer role.
⬜ An IdP group can be connected to only one GitHub team.
An enterprise uses personal accounts and wants to sync organization teams with IdP groups. Which IdPs support team synchronization in this setup?
⬜ Microsoft Entra ID or Okta
⬜ Any SAML 2.0 identity provider
⬜ PingFederate only
⬜ OneLogin or Shibboleth
An organization owner requires two-factor authentication. What happens to people who don’t have it enabled? (select two)
⬜ Outside collaborators without 2FA are removed and lose access to the organization’s repositories.
⬜ Members without 2FA stay members but can’t access the organization’s resources until they enable it.
⬜ Members without 2FA are removed and stop consuming licenses.
⬜ Outside collaborators get a 30-day grace period before losing access.
⬜ Everyone without 2FA keeps access but is shown a warning banner.
An organization requires 2FA and turns on Only allow secure two-factor methods. Which method doesn’t count as secure?
⬜ SMS text messages
⬜ Passkeys
⬜ Security keys
⬜ The GitHub Mobile app
An enterprise owner of an enterprise with managed users wants to require two-factor authentication on GitHub. What should they know?
⬜ GitHub’s 2FA requirement isn’t available for enterprises with managed users; authentication, including MFA, is handled by the IdP.
⬜ It must be enabled separately in each organization.
⬜ It applies only to the setup user.
⬜ It removes managed users who don’t enable 2FA within three months.
An enterprise that uses personal accounts has several organizations, some with their own SAML configurations. The enterprise owner configures and enforces SAML SSO at the enterprise level. Which statements are correct? (select two)
⬜ The enterprise configuration overrides the existing organization-level SAML configurations.
⬜ Members who haven’t authenticated with the IdP aren’t removed; they authenticate the next time they access enterprise resources.
⬜ Each organization keeps its own IdP and the enterprise IdP becomes a fallback.
⬜ SCIM provisioning becomes available for all organizations in the enterprise.
⬜ Members who haven’t authenticated are removed from their organizations.
An organization owner revokes a member’s SAML authorization for a personal access token. What is the effect?
⬜ The token can no longer access the organization, but it still exists and works elsewhere.
⬜ The token is permanently deleted from the user’s account.
⬜ The member’s linked SAML identity is removed.
⬜ The member is removed from the organization.
An owner gives a member the GitHub App manager role for an organization. What can that member do?
⬜ Manage the settings of the organization’s GitHub App registrations, but not install or uninstall apps.
⬜ Install and uninstall any GitHub App on the organization’s repositories.
⬜ Approve OAuth app access requests for the organization.
⬜ Create custom repository roles for the organization.
A platform team should manage GitHub Actions policies, runners, runner groups, hosted compute network configurations and Actions secrets for an organization, without becoming owners. Which predefined organization role fits?
⬜ CI/CD admin
⬜ All-repository admin
⬜ App Manager
⬜ Security manager
A project manager needs to manage a repository’s topics and settings without access to sensitive or destructive actions such as deleting it. Which repository role fits?
⬜ Maintain
⬜ Triage
⬜ Write
⬜ Admin
An organization on GitHub Enterprise Cloud is designing custom repository roles. Which statements are correct? (select two)
⬜ Each custom role starts from an inherited role of Read, Triage, Write or Maintain.
⬜ The organization can create up to 20 custom repository roles.
⬜ A custom role can inherit from the Admin role.
⬜ When a person has several roles, the most restrictive role wins.
⬜ Custom repository roles are available on GitHub Team plans.
An organization creates a custom organization role that includes a base repository role of Write. What does that repository permission apply to?
⬜ All current and future repositories in the organization
⬜ Only repositories created after the role is assigned
⬜ Only repositories the role holder already belongs to through a team
⬜ Only public repositories in the organization
What can an enterprise owner do by default with the organizations in their enterprise?
⬜ Manage enterprise settings and policies, but not see organization settings or content unless they join the organization.
⬜ Read every repository in every organization without joining.
⬜ Push to any repository in the enterprise.
⬜ Edit every organization’s settings without joining it.
An enterprise with managed users wants contractors who can work in specific repositories but can’t see the enterprise’s internal repositories. How is this set up?
⬜ Assign them the guest collaborator role in the IdP, which sends the role value guest_collaborator.
⬜ Invite their personal GitHub accounts as outside collaborators.
⬜ Make them enterprise billing managers.
⬜ Add them to an enterprise team with no organization assignments.
Which statements about enterprise teams are correct? (select three)
⬜ They can be assigned Copilot Business licenses directly from the enterprise.
⬜ They can be added to organizations, where organization admins can give them more access.
⬜ They don’t support nested teams or team maintainers.
⬜ They can be designated as code owners in a CODEOWNERS file.
⬜ They’re limited to one organization each.
⬜ They can be made secret teams.
A repository has two active rulesets and a branch protection rule that target main, and their pull request review settings conflict. What happens?
⬜ All the rules apply, and the most restrictive version of the conflicting rule wins.
⬜ The most recently created ruleset takes priority.
⬜ The branch protection rule overrides the rulesets.
⬜ GitHub disables the rulesets until the conflict is resolved.
An organization wants to test a new ruleset on its repositories and see what it would block, without blocking anyone yet. Which ruleset status should it use?
⬜ Evaluate
⬜ Active
⬜ Disabled
⬜ Draft
An organization sets its base permission to Read. A consultant who is an outside collaborator has Write access to one repository. What access does the consultant have to the organization’s other repositories?
⬜ None; base permissions don’t apply to outside collaborators.
⬜ Read, because base permissions apply to everyone with repository access.
⬜ Write, because their highest access applies everywhere.
⬜ Read on internal repositories only.
For a compliance review, an organization owner on GitHub Enterprise Cloud needs a file listing everyone with access to a repository. Where can they get it?
⬜ From the repository’s Insights tab, on the People page, using Export CSV
⬜ From the organization audit log, using Export JSON only
⬜ From the repository’s Settings > Collaborators page, using Download list
⬜ By asking GitHub Support for an access report
An administrator finds a token beginning with ghs_ in a log file. What kind of token is it?
⬜ A GitHub App installation access token
⬜ A personal access token (classic)
⬜ A fine-grained personal access token
⬜ An OAuth app access token
An enterprise owner wants to stop members from forking private and internal repositories in every organization. Where is this set?
⬜ In the enterprise’s repository management policies
⬜ In each repository’s branch rulesets
⬜ In the enterprise IP allow list
⬜ In each user’s personal settings
An enterprise owner requires SSH certificates for access to the enterprise’s organizations. What is the effect on other access methods?
⬜ Git over HTTPS and unsigned SSH keys are blocked, but GitHub Apps, deploy keys, GitHub Actions and Codespaces aren’t affected.
⬜ Only Git over HTTPS is blocked; unsigned SSH keys keep working.
⬜ Every access method, including GitHub Actions, must use a certificate.
⬜ Deploy keys must be replaced with certificates signed by the enterprise CA.
Domain 2: Administer GitHub Enterprise environment (10–15%)
An enterprise owner is deciding which requests to send to GitHub Support. Which topics does GitHub Support generally treat as out of scope? (select three)
⬜ Configuring the company’s SAML identity provider
⬜ Writing scripts for the company’s automation
⬜ Problems with a third-party CI system such as Jenkins
⬜ A GitHub Enterprise Server instance that won’t start after an upgrade
⬜ Unexpected errors from a GitHub REST API endpoint
Who automatically has a support entitlement to open tickets for a GitHub Enterprise account?
⬜ Enterprise owners and billing managers
⬜ Every member of every organization in the enterprise
⬜ Organization owners only
⬜ Repository administrators only
A team reports a suspected security incident to GitHub Support and asks for a screen-sharing call. How does Support handle security matters?
⬜ In writing through the support ticket; callback and screen-share requests can’t be accommodated.
⬜ Only by phone, to avoid putting details in writing.
⬜ Through a screen-sharing session, scheduled within 30 minutes.
⬜ Only through the community forum.
An enterprise has GitHub Premium Support and opens an Urgent ticket. What initial response time does the SLA guarantee?
⬜ 30 minutes
⬜ 4 hours
⬜ 8 hours
⬜ 24 hours
Which benefits does Premium Plus Support include that Premium Support doesn’t? (select three)
⬜ A named Customer Reliability Engineer
⬜ Quarterly enhanced health checks, by request
⬜ Technical advisory hours each quarter
⬜ A 30-minute initial response for Urgent tickets
⬜ 24/7 availability for written tickets
⬜ Escalation management for High and Urgent tickets
A GitHub Enterprise Server administrator is choosing a ticket priority. Which situations match the High priority definition? (select two)
⬜ One node of a high-availability pair has failed, reducing redundancy.
⬜ SCIM user or group provisioning is failing.
⬜ The production instance is down for all users and core Git operations fail.
⬜ The team wants to request a new feature.
⬜ API calls are failing because of rate limiting.
What is the difference between a GitHub Enterprise Server diagnostics file and a support bundle?
⬜ A diagnostics file is plain text about the instance’s settings and environment; a support bundle is a compressed archive with diagnostics plus sanitized logs.
⬜ A diagnostics file contains the instance’s repositories; a support bundle contains only settings.
⬜ A diagnostics file is encrypted for GitHub Support only; a support bundle is readable by anyone.
⬜ They’re the same file with different names.
GitHub Support asks a GitHub Enterprise Server administrator for logs covering the past week. How should the administrator create the bundle?
⬜ Run ghe-support-bundle -x over SSH to create an extended bundle with eight days of logs.
⬜ Click Download support bundle in the Management Console, which always includes 30 days of logs.
⬜ Download an extended bundle from the Management Console’s Support page.
⬜ Run ghe-diagnostics -x to add a week of logs to the diagnostics file.
A GitHub Enterprise Server deployment uses clustering. Which command should the administrator use to send GitHub Support a bundle and associate it with an existing ticket?
⬜
ssh -p 122 admin@HOSTNAME -- 'ghe-cluster-support-bundle -t TICKET_ID'
⬜
ssh -p 122 admin@HOSTNAME -- 'ghe-diagnostics -t TICKET_ID'
⬜
ssh -p 22 admin@HOSTNAME -- 'ghe-support-bundle --ticket TICKET_ID'
⬜
ssh -p 122 admin@HOSTNAME -- 'ghe-cluster-support-bundle -o' > bundle.tgz
A GitHub Enterprise Server administrator wants to upload a support bundle straight from the instance with ghe-support-bundle -u. What network access does this need?
⬜ Outbound HTTPS (TCP 443) to enterprise-bundles.github.com and esbtoolsproduction.blob.core.windows.net
⬜ Inbound SSH on port 122 from GitHub’s support network
⬜ Outbound SMTP so the bundle can be emailed to Support
⬜ No network access, because the bundle is sent through GitHub Connect
Which GitHub Enterprise Server command-line utility validates the instance’s configuration files and checks individual options?
⬜ ghe-config-check
⬜ ghe-check-disk-usage
⬜ ghe-maintenance
⬜ ghe-cluster-support-bundle
A European company must keep its code and data stored in the EU while using GitHub’s cloud. Which deployment fits?
⬜ GitHub Enterprise Cloud with data residency on a GHE.com subdomain, with Enterprise Managed Users
⬜ GitHub Enterprise Cloud on GitHub.com with personal accounts and SAML SSO
⬜ GitHub Enterprise Cloud on GitHub.com with Enterprise Managed Users
⬜ GitHub Team with an EU billing address
A company is moving to GitHub Enterprise Cloud with data residency on GHE.com. Which statements should it plan for? (select two)
⬜ Public repositories aren’t available.
⬜ IP ranges and SSH key fingerprints differ from GitHub.com, so client network access needs updating.
⬜ Developers can keep using their personal GitHub.com accounts.
⬜ Every GitHub.com feature is available in the same form.
⬜ Data is always stored in the US, with backups in the chosen region.
A company runs GitHub Enterprise Server on its own infrastructure but wants Dependabot alerts, which rely on GitHub.com data. What enables this?
⬜ GitHub Connect
⬜ Converting the instance to GitHub Enterprise Cloud with data residency
⬜ Enterprise Managed Users
⬜ A GitHub Premium Support contract
An existing GitHub Enterprise Cloud enterprise uses personal accounts. Leadership wants to adopt Enterprise Managed Users. What does this involve?
⬜ Migrating to a new enterprise account set up for Enterprise Managed Users
⬜ Turning on a setting in the existing enterprise’s authentication settings
⬜ Configuring SCIM at the enterprise level on the existing account
⬜ Asking every user to rename their personal account with the enterprise shortcode
A company’s developers maintain several open source projects under the company’s name and contribute to other public projects. Which GitHub Enterprise Cloud setup fits best?
⬜ An enterprise with personal accounts, optionally with SAML SSO
⬜ An enterprise with Enterprise Managed Users
⬜ GitHub Enterprise Cloud with data residency
⬜ An enterprise with Enterprise Managed Users and guest collaborators
An enterprise on usage-based licensing adds 10 users, later adds 20 more, then removes 5 during the same billing cycle. How many consumed and billable licenses does it have?
⬜ 25 consumed and 30 billable
⬜ 25 consumed and 25 billable
⬜ 30 consumed and 25 billable
⬜ 35 consumed and 35 billable
Which statements about usage-based billing for GitHub Enterprise licenses are correct? (select two)
⬜ It applies to GitHub Enterprise Cloud trials created on or after August 1, 2024.
⬜ A user who starts mid-cycle is billed pro rata for that month.
⬜ Pending organization invitations consume a license.
⬜ Existing volume agreements must switch immediately.
⬜ It requires committing to a fixed number of licenses in advance.
In a GitHub Enterprise Cloud enterprise, which of these consume a license? (select two)
⬜ An outside collaborator on a private repository
⬜ A dormant user who belongs to at least one organization in the enterprise
⬜ An enterprise billing manager
⬜ A suspended managed user account
⬜ An outside collaborator on a public repository only
An enterprise owner of GitHub Enterprise Cloud isn’t a member of any organization in the enterprise. Do they consume a license?
⬜ No; enterprise owners only consume a license if they belong to at least one organization in the enterprise.
⬜ Yes; every enterprise owner always consumes a license.
⬜ Yes, but only if they have 2FA enabled.
⬜ No, unless they’re also a billing manager.
On GitHub Enterprise Server, which accounts consume a license?
⬜ Active users who have authenticated to the instance, including dormant users who aren’t suspended
⬜ Only users who pushed code in the last 90 days
⬜ Suspended users, until they’re deleted
⬜ Only site administrators
A GitHub Enterprise Server instance has GitHub Connect enabled with license sync. How often is license usage synced to GitHub Enterprise Cloud automatically?
⬜ Weekly, with the option to trigger a sync manually
⬜ Every hour
⬜ Daily at midnight UTC
⬜ Only when an administrator uploads a file
A billing manager needs a file listing the license usage of an enterprise on GitHub Enterprise Cloud. Where can they get it?
⬜ On the enterprise’s Licensing page, using Download CSV report
⬜ From each organization’s People page, combined manually
⬜ From the enterprise audit log export
⬜ Only by asking GitHub Support
An organization standardizes reviews with CODEOWNERS files. Which statements are correct? (select three)
⬜ The file can be in the .github/, root or docs/ directory; if several exist, the first one found in that order is used.
⬜ When several patterns match a file, the last matching pattern takes precedence.
⬜ Code owners must have write permission on the repository.
⬜ When several patterns match a file, the first matching pattern takes precedence.
⬜ Code owner reviews are required automatically, without any branch protection or ruleset.
An organization’s review standard says the person who pushed the latest change to a pull request can’t be the one who approves it. Which branch protection setting enforces this?
⬜ Require approval of the most recent reviewable push
⬜ Dismiss stale pull request approvals when new commits are pushed
⬜ Require conversation resolution before merging
⬜ Require linear history
An organization turns on a merge queue for main in its private repositories on GitHub Enterprise Cloud. Its required checks run in GitHub Actions. What must the workflows include?
⬜ The merge_group event as a trigger
⬜ The pull_request_target event as a trigger
⬜ A concurrency group named merge-queue
⬜ The workflow_run event as a trigger
A team is writing release standards for its GitHub repositories. Which statements about releases are correct? (select two)
⬜ Releases are based on Git tags.
⬜ A single release can have up to 1,000 assets, each under 2 GiB.
⬜ Anyone with read access can create or edit releases.
⬜ Total release size is limited to 10 GiB.
⬜ Release notes must always be written by hand.
Domain 3: Implement secure software development and compliance (25–30%)
An organization owner turns on an IP allow list. Which kinds of access does it restrict? (select three)
⬜ Web UI access by signed-in users
⬜ API calls made with personal access tokens
⬜ Git operations using SSH keys
⬜ Anonymous access to the organization’s public repositories
⬜ Email notifications sent by GitHub to members
An organization with an IP allow list installs a GitHub App that publishes its own IP addresses. How can the app keep working without the owner adding its IPs manually?
⬜ Turn on Enable IP allow list configuration for installed GitHub Apps.
⬜ Add 0.0.0.0/0 to the allow list for app traffic only.
⬜ Exempt the app by giving it the GitHub App manager role.
⬜ Disable the allow list whenever the app runs.
An enterprise owner has configured an IP allow list for the enterprise. What can owners of its organizations do with those entries?
⬜ They inherit them and can add their own entries, but can’t manage the inherited ones.
⬜ They can delete inherited entries that don’t apply to their organization.
⬜ They must recreate the entries in each organization for them to apply.
⬜ They can turn the enterprise list off for their organization.
An organization uses an IP allow list and wants to keep running GitHub Actions workflows. What does GitHub say it needs?
⬜ Self-hosted runners or GitHub-hosted larger runners with static IP ranges, with those IPs added to the allow list
⬜ Standard GitHub-hosted runners, because their traffic is exempt from allow lists
⬜ A permissions: ip-allowlist: bypass setting in each workflow
⬜ Nothing; Actions isn’t affected by IP allow lists
Where does secret scanning look for leaked credentials in a repository? (select three)
⬜ The entire Git history on all branches
⬜ Issue descriptions and comments
⬜ Pull request titles, descriptions and comments
⬜ The CI logs of third-party build systems
⬜ Developers’ local working copies that haven’t been pushed
An organization on GitHub Enterprise Cloud wants secret scanning alerts for its private and internal repositories. What does it need?
⬜ GitHub Secret Protection
⬜ GitHub Code Security
⬜ Nothing; secret scanning is free for all repositories
⬜ GitHub Copilot Business
Secret scanning finds a token issued by one of GitHub’s secret scanning partners. What happens?
⬜ GitHub notifies the provider so it can take action, such as revoking the credential.
⬜ GitHub revokes the token itself and deletes the commit.
⬜ GitHub blocks the repository until an owner removes the secret.
⬜ Nothing until an administrator turns on validity checks.
Which statements about push protection are correct? (select two)
⬜ Repository push protection requires GitHub Secret Protection and is turned off by default.
⬜ User push protection is on by default and stops you from pushing supported secrets to public repositories.
⬜ Push protection only checks pushes from the command line.
⬜ Only organization owners can bypass a push protection block.
⬜ Push protection removes the secret from the commit automatically.
A developer’s push is blocked by push protection. They bypass it by choosing I’ll fix it later. What does GitHub record?
⬜ An open secret scanning alert
⬜ A closed alert marked as a false positive
⬜ A closed alert marked as used in tests
⬜ No alert, because the push was allowed
A security team wants contributors to ask for approval before bypassing push protection. What is true about delegated bypass?
⬜ Blocked contributors submit bypass requests, and requests expire after 7 days.
⬜ Requests never expire until a reviewer responds.
⬜ Only enterprise owners can review bypass requests.
⬜ It works only for pushes from the command line.
An organization defines a custom secret scanning pattern for its internal API keys. Which statements are correct? (select two)
⬜ Save and dry run shows sample matches without creating alerts.
⬜ Push protection can be turned on for the pattern only after it’s published.
⬜ Custom patterns can only be defined at the enterprise level.
⬜ A dry run creates alerts that are hidden from repository admins.
⬜ Custom patterns are applied only to new commits, never to history.
A secret scanning alert shows a validity status of active. What does that mean?
⬜ GitHub checked with the provider and the secret could still be used, so it should be dealt with first.
⬜ The alert is still open, whatever the state of the secret.
⬜ GitHub couldn’t verify the secret with the provider.
⬜ The provider has already revoked the secret.
A developer committed a cloud access key, and a secret scanning alert was raised. What is the most important first remediation step?
⬜ Revoke the secret with its provider.
⬜ Rewrite the repository history to remove the commit.
⬜ Close the alert as a false positive.
⬜ Make the repository private.
Which features belong to GitHub Secret Protection rather than GitHub Code Security? (select two)
⬜ Push protection
⬜ Custom secret scanning patterns
⬜ CodeQL code scanning
⬜ Copilot Autofix
⬜ Dependency review
On which plans can organizations buy GitHub Secret Protection and GitHub Code Security?
⬜ GitHub Team and GitHub Enterprise Cloud
⬜ GitHub Enterprise Cloud only
⬜ GitHub Free and GitHub Pro
⬜ GitHub Enterprise Server only
How does GitHub decide whether someone counts as an active committer for GitHub Secret Protection or Code Security billing?
⬜ One of their commits was pushed to a repository with the product enabled in the last 90 days.
⬜ They authored a commit in the last 30 days, whenever it was pushed.
⬜ They opened a pull request in any repository in the last year.
⬜ They’re a member of the organization, whether or not they commit.
What does an enterprise policy that disallows GitHub Code Security for an organization do?
⬜ Stops repository admins enabling it on new repositories, but doesn’t turn it off where it’s already on.
⬜ Turns Code Security off immediately in every repository in that organization.
⬜ Stops organization owners and security managers from enabling it.
⬜ Deletes existing code scanning alerts.
An organization wants to apply the same set of security feature settings across many repositories. What should it use?
⬜ Security configurations
⬜ Repository rulesets
⬜ Custom repository roles
⬜ Workflow templates
Who can see security overview data for all repositories in an organization?
⬜ Organization owners and security managers
⬜ Every organization member
⬜ Only enterprise owners
⬜ Only repository admins
A team wants to enable CodeQL code scanning with default setup on a private organization repository. What are the requirements? (select two)
⬜ GitHub Actions must be enabled for the repository.
⬜ The repository must have GitHub Code Security enabled.
⬜ A codeql.yml workflow must already be committed.
⬜ The repository must use self-hosted runners.
⬜ GitHub Secret Protection must be enabled.
A repository with CodeQL default setup gets no pushes or pull requests for six months. What happens to its weekly scheduled scan?
⬜ The weekly schedule is disabled to save GitHub Actions minutes.
⬜ It keeps running every week indefinitely.
⬜ Default setup is removed and an advanced workflow is created.
⬜ The repository is archived automatically.
An organization wants CodeQL default setup to run on a GitHub-hosted larger runner. What must it do?
⬜ Name the larger runner code-scanning; an organization can have only one larger runner with that label.
⬜ Add runs-on: larger to the default setup workflow file.
⬜ Switch every repository to advanced setup.
⬜ Ask GitHub Support to assign a runner.
A repository has an advanced setup CodeQL workflow, and an admin switches the repository to default setup. What happens?
⬜ Default setup overrides the existing configuration, disabling the workflow file and blocking CodeQL uploads through the API.
⬜ Both configurations run side by side.
⬜ The switch is refused until the workflow file is deleted.
⬜ Default setup imports the custom queries from the workflow.
When does code scanning advanced setup make more sense than default setup?
⬜ When you need a highly customizable configuration that you edit as a workflow file
⬜ When you want the quickest way to start scanning with no configuration
⬜ When GitHub Actions is disabled for the repository
⬜ When the repository is public and doesn’t need Code Security
When does GitHub generate Dependabot alerts for a repository? (select two)
⬜ When a new vulnerability affecting a dependency is added to the GitHub Advisory Database
⬜ When the dependency graph changes, for example when a commit updates a package version
⬜ When a developer opens any pull request
⬜ Every night, whether or not anything has changed
⬜ When a secret is found in a dependency’s manifest
A repository’s workflows pin third-party actions to full commit SHAs. What should the security team know about Dependabot alerts for these actions?
⬜ Dependabot alerts are only generated for actions referenced by semantic version, not by SHA.
⬜ Dependabot alerts for SHA-pinned actions are raised daily.
⬜ SHA pinning sends the alerts to the action’s maintainer instead.
⬜ SHA-pinned actions are scanned only if CodeQL is enabled.
An organization uses Dependabot auto-triage rules to auto-dismiss low-risk alerts. What happens to notifications for those alerts?
⬜ None are sent, because the rules are applied before notifications go out.
⬜ Notifications are sent and then retracted.
⬜ Only repository admins are notified.
⬜ Notifications are delayed by 24 hours.
What does a Dependabot security update do?
⬜ Opens a pull request that updates the vulnerable dependency to the minimum version with the patch.
⬜ Updates every dependency to its latest version daily.
⬜ Patches the dependency’s source code in place.
⬜ Merges the fix automatically without a pull request.
A Dependabot alert has no security update pull request. What could explain this? (select two)
⬜ No patched version of the dependency exists yet.
⬜ The update would break the dependency graph, so Dependabot reports an error on the alert instead.
⬜ Security updates only run once a month.
⬜ The repository has more than 100 open alerts.
⬜ Security updates only run for public repositories.
A team groups Dependabot security updates to reduce the number of pull requests. What will Dependabot never put in the same group?
⬜ Dependencies from different package ecosystems, or security updates together with version updates
⬜ Two dependencies from the same ecosystem
⬜ Dependencies listed in the same manifest file
⬜ Updates for development and production dependencies of one ecosystem
Which dependabot.yml file is valid for weekly npm version updates in the repository root?
⬜
version: 2
updates:
- package-ecosystem: "npm"
directory: "/"
schedule:
interval: "weekly"
⬜
version: 1
updates:
- package-ecosystem: "npm"
directory: "/"
schedule:
interval: "weekly"
⬜
version: 2
updates:
- package-ecosystem: "npm"
directory: "/"
schedule:
interval: "hourly"
⬜
version: 2
dependencies:
- ecosystem: "npm"
path: "/"
frequency: "weekly"
A team notices that Dependabot version update pull requests appear a few days after a new package version is released, even though cooldown isn’t configured. Why?
⬜ Dependabot applies a default cooldown of 3 days to version updates.
⬜ Dependabot only checks registries once a week.
⬜ New versions are hidden until the GitHub Advisory Database reviews them.
⬜ The repository has hit its open pull request limit.
What do Dependabot version updates do that security updates don’t?
⬜ Keep dependencies current even when they have no known vulnerabilities.
⬜ Raise pull requests only for dependencies with a Dependabot alert.
⬜ Work without any configuration file.
⬜ Update only to the minimum patched version.
A team wants pull requests that add vulnerable dependencies or disallowed licenses to fail a required check. What should it use?
⬜ The dependency review action, configured with a severity threshold and a license allow or deny list
⬜ Dependabot security updates
⬜ Secret scanning custom patterns
⬜ The repository’s security policy file
A maintainer receives a private report of a vulnerability in a public repository. What can they do with a repository security advisory? (select three)
⬜ Discuss the vulnerability privately in a draft advisory.
⬜ Work on a fix in a temporary private fork.
⬜ Request a CVE identification number from GitHub.
⬜ Hide the repository from GitHub search until the fix is merged.
⬜ Send the fix to every dependent repository as an automatic commit.
Who can turn on private vulnerability reporting, and for which repositories?
⬜ Owners and administrators of public repositories
⬜ Any contributor, for any repository
⬜ Enterprise owners only, for internal repositories
⬜ Security managers only, for private repositories
An organization wants one SECURITY.md to apply to every repository that doesn’t have its own. Which statements are correct? (select two)
⬜ Put it in a repository named .github that is public or internal.
⬜ A repository’s own SECURITY.md takes precedence over the default.
⬜ The .github repository must be private.
⬜ The default file also replaces the security policies of repositories that have their own.
⬜ The same approach can provide a default LICENSE file.
What should a repository’s SECURITY.md security policy include?
⬜ Which versions of the project are supported and how to report a vulnerability
⬜ A list of all known unpatched vulnerabilities
⬜ The secrets used by the project’s workflows
⬜ The members of the security team and their personal phone numbers
An enterprise is preparing for future security incidents. Which steps does GitHub recommend? (select three)
⬜ Stream the enterprise audit log to a SIEM.
⬜ Turn on streaming of API request events.
⬜ Create and maintain a Security Incident Response Plan.
⬜ Turn off audit logging to reduce noise.
⬜ Give every developer enterprise owner access so they can respond quickly.
⬜ Keep identity provider logs only for 24 hours.
During a security incident, a compromised personal access token is found. What does GitHub describe as the most immediate action?
⬜ Revoke the affected credentials.
⬜ Write the incident summary.
⬜ Wait until the root cause analysis is finished.
⬜ Notify all customers before doing anything else.
Which statements correctly compare fine-grained personal access tokens with personal access tokens (classic)? (select three)
⬜ A fine-grained token has a single resource owner, a user or an organization.
⬜ A fine-grained token can be limited to selected repositories.
⬜ Organization owners can require approval for fine-grained tokens.
⬜ Classic tokens can be limited to selected repositories.
⬜ Fine-grained tokens can call APIs that manage the enterprise account.
⬜ Classic tokens are subject to the organization’s approval policy.
A consultant is an outside collaborator on one of an organization’s repositories and wants to script pushes with a token. What should they know?
⬜ Fine-grained tokens can’t contribute to repositories where the user is an outside collaborator; a classic token can.
⬜ Fine-grained tokens work for outside collaborators once the organization approves them.
⬜ Outside collaborators can’t use any personal access token.
⬜ Only GitHub Apps can push for outside collaborators.
What is the maximum number of fine-grained personal access tokens a user can have?
⬜ 50
⬜ 10
⬜ 100
⬜ Unlimited
An organization owner sets a maximum lifetime for personal access tokens. A member already has a token that exceeds it. What happens?
⬜ The token isn’t revoked, but it’s blocked from the organization’s resources.
⬜ The token is revoked immediately.
⬜ The token’s expiration date is shortened automatically.
⬜ The token keeps working until it expires naturally.
An enterprise owner sets the fine-grained token access policy to Restrict access. What can organization owners do?
⬜ Nothing to override it; organizations can’t change an enterprise restrict or allow setting.
⬜ Override it for their own organization.
⬜ Allow fine-grained tokens for selected repositories.
⬜ Restrict only classic tokens instead.
An organization requires approval for fine-grained personal access tokens. A member creates one for the organization. What happens until an owner approves it?
⬜ It can’t access non-public organization resources.
⬜ It has full access but is flagged in the audit log.
⬜ It’s converted to a classic token.
⬜ It’s deleted after 24 hours.
An organization wants to automate reviews of fine-grained personal access token requests with the REST API. What must call those endpoints?
⬜ A GitHub App
⬜ A personal access token (classic) with admin:org scope
⬜ An OAuth app
⬜ A fine-grained personal access token owned by an organization owner
What is the primary REST API rate limit for a user authenticated with a personal access token?
⬜ 5,000 requests per hour, shared across the user’s credentials
⬜ 60 requests per hour
⬜ 15,000 requests per hour for every user
⬜ 1,000 requests per hour
A GitHub App is installed on an organization that uses GitHub Enterprise Cloud. What primary rate limit does its installation access token get?
⬜ 15,000 requests per hour
⬜ 5,000 requests per hour, fixed
⬜ 5,000 plus 50 per repository, up to 12,500
⬜ 60 requests per hour
A workflow in a repository owned by a GitHub Enterprise Cloud account uses GITHUB_TOKEN to call the REST API. What is the primary rate limit?
⬜ 15,000 requests per hour per repository
⬜ 1,000 requests per hour per repository
⬜ 5,000 requests per hour per user
⬜ Unlimited, because it’s an Actions token
An integration starts getting secondary rate limit responses from the REST API. Which practices does GitHub recommend or document? (select two)
⬜ If a retry-after header is present, wait that many seconds before retrying.
⬜ Keep concurrent requests under 100, a limit shared between REST and GraphQL.
⬜ Retry immediately in a tight loop until requests succeed.
⬜ Switch to unauthenticated requests to get a separate quota.
⬜ Ignore the limit, because secondary limits only apply to GraphQL.
Why does GitHub generally recommend GitHub Apps over OAuth apps for integrations? (select three)
⬜ GitHub Apps request fine-grained permissions instead of broad scopes.
⬜ GitHub Apps get access only to the repositories selected at installation.
⬜ GitHub Apps can act on their own, so automation keeps working if the installer leaves.
⬜ GitHub App installation tokens never expire.
⬜ GitHub Apps share the installing user’s rate limit.
⬜ GitHub Apps need a separate webhook for each repository.
An organization owner turns on OAuth app access restrictions for the first time. What happens? (select two)
⬜ Previously authorized OAuth apps immediately lose access to the organization’s resources, except apps owned by the organization.
⬜ Members can request owner approval for OAuth apps they want to use.
⬜ All GitHub Apps installed on the organization are uninstalled.
⬜ Members’ personal access tokens stop working.
⬜ The organization’s deploy keys are all deleted.
An organization owner wants only owners to install GitHub Apps, so repository admins must ask instead. Which setting does this?
⬜ Turn off Allow repository admins to install GitHub Apps for their repositories under Member privileges.
⬜ Turn on OAuth app access restrictions.
⬜ Remove the GitHub App manager role from everyone.
⬜ Add an IP allow list entry for each app.
When can a repository admin install a GitHub App on their organization’s repositories, if owners allow it?
⬜ When the app requests no organization permissions and no repository administration permission, and only on repositories they administer
⬜ Whenever the app is listed on GitHub Marketplace
⬜ Only when the app is installed on all repositories
⬜ Only after an enterprise owner approves it
How long does the GitHub Enterprise Cloud enterprise audit log keep events?
⬜ 180 days for audit events, and seven days for Git events
⬜ 90 days for all events
⬜ One year for audit events and 30 days for Git events
⬜ Indefinitely
An enterprise streams its audit log to a SIEM. Which statements are correct? (select three)
⬜ Supported endpoints include Amazon S3, Azure Event Hubs, Datadog and Splunk.
⬜ API request events aren’t streamed until you turn on Enable API Request Events.
⬜ A paused stream keeps a buffer of events for seven days.
⬜ Streaming is limited to audit events; Git events can’t be streamed.
⬜ Amazon S3 streaming only supports access keys, not OpenID Connect.
An audit log stream has been misconfigured. What does GitHub do?
⬜ The daily health check emails enterprise owners, who must fix it within six days to avoid dropped events.
⬜ GitHub silently drops events until someone notices.
⬜ GitHub switches the stream to the next configured endpoint automatically.
⬜ GitHub suspends all API access for the enterprise.
Repository push protection is off for a private organization repository that has GitHub Secret Protection. Who can turn it on? (select three)
⬜ A repository administrator
⬜ An organization owner
⬜ A security manager
⬜ Any user with write access
⬜ An outside collaborator with read access
Domain 4: Manage GitHub Actions (20–25%)
An enterprise wants to share a set of actions and reusable workflows with all its organizations without publishing them publicly. Which statements are correct? (select two)
⬜ They can be stored in an internal or private repository and shared with other repositories in the organization or enterprise.
⬜ Actions in an internal repository can’t be used by workflows in public repositories.
⬜ They must be published to GitHub Marketplace first.
⬜ Actions in a private repository can be used by internal and public repositories.
⬜ Sharing requires the organization to be on GitHub Team, not Enterprise Cloud.
A private repository shares a reusable workflow with other repositories in the organization. What risk does GitHub point out?
⬜ Outside collaborators on the calling repositories can indirectly access it, including through workflow run logs.
⬜ The workflow becomes visible to anyone on GitHub.com.
⬜ The workflow’s secrets are copied into every calling repository.
⬜ GitHub Support can modify the shared workflow.
What makes a workflow reusable by other workflows?
⬜ Its on value includes workflow_call.
⬜ It’s stored in .github/reusable/.
⬜ Its file name ends in .reusable.yml.
⬜ It includes workflow_dispatch with inputs.
A platform team builds a chain of reusable workflows that call each other. Which statements are correct? (select two)
⬜ At most ten levels of workflows can be connected, counting the top-level caller.
⬜ Secrets passed to a reusable workflow only reach the directly called workflow, so each level must pass them on.
⬜ Loops in the workflow chain are allowed if each loop runs once.
⬜ secrets: inherit works with reusable workflows in any organization on GitHub.com.
⬜ Outputs of steps in the called workflow are available to the caller without mapping them to job outputs.
An organization owner wants to offer a standard CI workflow template to everyone in the organization. Where do the files go?
⬜ In a workflow-templates directory of the organization’s .github repository, with a matching .properties.json metadata file
⬜ In .github/workflows of each repository
⬜ In the organization’s Settings > Actions > Templates page
⬜ In a templates branch of any repository
A workflow template uses $default-branch in its on.push.branches setting. What happens when someone creates a workflow from it?
⬜ It’s replaced with the repository’s default branch name.
⬜ It’s always replaced with main.
⬜ The workflow fails validation until the user edits it.
⬜ It matches every branch in the repository.
An enterprise owner chooses Allow enterprise actions and reusable workflows as the enterprise’s Actions policy. What is the side effect?
⬜ Actions authored by GitHub, such as actions/checkout, are blocked too.
⬜ Only Marketplace actions from verified creators are allowed.
⬜ Reusable workflows from other enterprises are still allowed.
⬜ Self-hosted runners are disabled.
An enterprise uses Allow enterprise, and select non-enterprise, actions and reusable workflows. Which extra choices are available? (select three)
⬜ Allow actions created by GitHub
⬜ Allow Marketplace actions by verified creators
⬜ Allow or block specified actions and reusable workflows, with wildcards and ! to block
⬜ Allow any action whose repository has more than 1,000 stars
⬜ Allow actions that have passed GitHub’s code review
An enterprise turns on Require actions to be pinned to a full-length commit SHA. Which reference is still allowed?
⬜ A reusable workflow referenced by tag, such as org/repo/.github/workflows/ci.yml@v2
⬜ An action referenced by major version tag, such as actions/checkout@v4
⬜ An action referenced by branch, such as org/action@main
⬜ An action referenced by a shortened SHA
For public repositories, which options can an organization choose to require approval before running workflows from fork pull requests? (select three)
⬜ Require approval for first-time contributors who are new to GitHub
⬜ Require approval for first-time contributors
⬜ Require approval for all external contributors
⬜ Require approval only for pull requests that change workflow files
⬜ Require approval only on weekends
Which settings control workflows from fork pull requests in private and internal repositories? (select three)
⬜ Run workflows from fork pull requests
⬜ Send secrets to workflows from pull requests
⬜ Require approval for fork pull request workflows
⬜ Allow forks to use enterprise runner groups automatically
⬜ Copy the base repository’s environments to the fork
What is the maximum artifact and log retention an enterprise can set for private and internal repositories?
⬜ 400 days
⬜ 90 days
⬜ 180 days
⬜ 365 days
An enterprise created in 2025 hasn’t changed its workflow permissions. What default permissions does GITHUB_TOKEN get?
⬜ Read-only access to repository contents and packages
⬜ Read and write access to all scopes
⬜ No permissions at all
⬜ Admin access to the repository
A team wants a workflow to open pull requests with GITHUB_TOKEN, but the requests fail. Which setting is likely off?
⬜ Allow GitHub Actions to create and approve pull requests, which is disabled by default
⬜ Require actions to be pinned to a full-length commit SHA
⬜ Send write tokens to workflows from pull requests
⬜ The organization’s IP allow list for GitHub Apps
An enterprise owner disables self-hosted runners for all organizations. What is the effect?
⬜ Runners can’t be added at repository level, but enterprise and organization runners stay available to workflows.
⬜ All self-hosted runners, at every level, are removed.
⬜ Workflows can only use larger runners.
⬜ Organizations can re-enable repository-level runners in their own settings.
An enterprise wants all jobs to run on approved runners only, and disables standard GitHub-hosted runners for all organizations. How must workflows target runners afterwards?
⬜ Through runner groups
⬜ With the ubuntu-latest label only
⬜ By adding allow-standard: true to each job
⬜ Through the enterprise IP allow list
Which statements about self-hosted runner groups are correct? (select three)
⬜ Every organization has a single default runner group, which new runners join unless another group is chosen.
⬜ An enterprise runner group can be shared with all organizations or a selected list.
⬜ A runner group can be limited to a specific list of workflows.
⬜ By default, public repositories can use runners in any group.
⬜ Only enterprise owners can create organization runner groups.
Why does GitHub recommend using self-hosted runners only with private repositories?
⬜ Forks of public repositories could run dangerous code on the runner machine through pull requests.
⬜ Self-hosted runners can’t connect to public repositories.
⬜ Public repositories are billed per minute on self-hosted runners.
⬜ GitHub Support doesn’t allow self-hosted runners for public repositories.
What do GitHub-hosted larger runners offer compared with standard GitHub-hosted runners? (select three)
⬜ More CPU, RAM and disk space
⬜ Static IP addresses on Linux and Windows runners
⬜ Azure private networking on Linux and Windows runners
⬜ Use of the plan’s included minutes in private repositories
⬜ Free use in public repositories
A team needs a static IP address for a GitHub-hosted larger runner on macOS. What should they know?
⬜ Static IPs, custom images and Azure private networking are only available on Linux and Windows larger runners.
⬜ Static IPs are available on macOS larger runners after enabling them in the runner group.
⬜ Static IPs require Azure private networking on macOS.
⬜ All GitHub-hosted runners, including standard ones, can get static IPs.
An enterprise configures Azure private networking for GitHub-hosted runners. Which statements are correct? (select three)
⬜ The runner’s network interface is deployed into the company’s Azure VNet.
⬜ Network security group rules on the VNet apply to the runners.
⬜ Runners are deployed in the same Azure region as the connected subnet.
⬜ Standard GitHub-hosted runners can use the configuration.
⬜ Runners keep static public IP addresses as well.
By default, who can create Azure private networking configurations for GitHub-hosted runners in an enterprise?
⬜ Enterprise owners, at the enterprise level; organizations inherit them unless owners allow organizations to create their own.
⬜ Any repository administrator.
⬜ Only GitHub Support.
⬜ Any organization member with access to Azure.
A security team wants to allowlist the IP addresses of standard GitHub-hosted runners for internal resources. What does GitHub advise?
⬜ Don’t use them as allowlists, because the list is large and updated weekly; use larger runners with static IPs or self-hosted runners instead.
⬜ Add the actions ranges from GET /meta once; they never change.
⬜ Ask GitHub Support for a dedicated IP for each standard runner.
⬜ Allowlist 0.0.0.0/0 for runner traffic.
At which levels can self-hosted runners be added?
⬜ Repository, organization and enterprise
⬜ Repository only
⬜ Organization and enterprise only
⬜ Enterprise only
What does a self-hosted runner update automatically?
⬜ Only the runner application; the operating system and other software are your responsibility.
⬜ The runner application, the operating system and all installed tools.
⬜ Nothing; all updates must be installed manually.
⬜ Only the operating system.
Which statements about self-hosted runner operation are correct? (select two)
⬜ The host must be able to make outbound HTTPS connections on port 443.
⬜ A job that stays queued for more than 24 hours fails.
⬜ GitHub must be able to open inbound connections to the runner on port 22.
⬜ Ephemeral runners process up to ten jobs before deregistering.
⬜ Only Ubuntu is supported as a host operating system.
A self-hosted runner shows Offline in the organization’s runner list. What could cause this?
⬜ The machine is off, the runner application isn’t running, or it can’t reach GitHub.
⬜ The runner is executing a job.
⬜ The runner is connected and waiting for jobs.
⬜ The runner is in a group limited to selected workflows.
A self-hosted runner can’t connect to GitHub. Which command checks its access to the required GitHub services?
⬜
./config.sh --check --url URL --pat TOKEN
⬜
./run.sh --diagnose
⬜
./svc.sh status
⬜
./config.sh remove --token TOKEN
Where are a self-hosted runner’s log files, and what do they contain? (select two)
⬜ In the _diag directory where the runner application is installed
⬜ Worker_ files, with one detailed log per job
⬜ In the repository’s Actions tab only
⬜ In /var/log/github-runner/ on every OS
⬜ In a single file that’s overwritten each time the runner starts
A Linux self-hosted runner fails container jobs with dial unix /var/run/docker.sock: connect: permission denied. What’s the likely cause?
⬜ The runner’s service account doesn’t have permission to use Docker.
⬜ Docker isn’t supported on Linux runners.
⬜ The runner’s PAT is missing the workflow scope.
⬜ The job exceeded the 24-hour queue limit.
A platform team wants self-hosted runners that scale automatically on Kubernetes. What does GitHub provide?
⬜ Actions Runner Controller, a Kubernetes operator installed with Helm that manages runner scale sets
⬜ Azure private networking
⬜ A larger runner with the kubernetes label
⬜ The runs-on: kubernetes workflow keyword
At which levels can GitHub Actions secrets be stored? (select three)
⬜ Organization
⬜ Repository
⬜ Environment
⬜ Workflow file
⬜ Runner
A secret called DEPLOY_KEY exists at organization level, repository level and in the repository’s prod environment. A job uses environment: prod. Which value does it get?
⬜ The environment secret
⬜ The repository secret
⬜ The organization secret
⬜ The workflow fails because of the conflict
Which secret names are invalid? (select two)
⬜ GITHUB_DEPLOY_TOKEN
⬜ 1PASSWORD_KEY
⬜ DEPLOY_TOKEN
⬜ aws_access_key_id
⬜ NPM_TOKEN_2
What limits apply to GitHub Actions secrets? (select three)
⬜ Up to 1,000 organization secrets
⬜ Up to 100 repository secrets
⬜ Each secret can be up to 48 KB
⬜ Up to 10 environment secrets
⬜ Each secret can be up to 1 MB
An organization owner creates an organization secret for a database password. How can they limit which repositories use it?
⬜ Set its repository access to all repositories, private repositories only, or a selected list.
⬜ Use an IP allow list on the secret.
⬜ Put the secret in a runner group.
⬜ Encrypt it with each repository’s deploy key.
A team wants a production secret used only after a named approver signs off on each deployment. What should it use?
⬜ An environment secret on an environment with required reviewers
⬜ An organization secret limited to private repositories
⬜ A repository secret with a long, complex name
⬜ A secret referenced inside an if: condition
What repository access does someone need to create environment secrets in an organization repository?
⬜ Admin
⬜ Write
⬜ Triage
⬜ Read
Which statements about secrets in workflows are correct? (select three)
⬜ Secrets aren’t passed to workflows triggered from forks, except GITHUB_TOKEN.
⬜ Secrets aren’t available to workflows triggered by Dependabot events.
⬜ Secrets aren’t passed to reusable workflows automatically.
⬜ Secrets can be referenced directly in if: conditions.
⬜ Secret values are guaranteed never to appear in logs.
When are environment secrets read during a workflow run?
⬜ When a job that references the environment starts
⬜ When the workflow run is queued
⬜ When the workflow file is committed
⬜ When the runner registers with GitHub
Why should teams use OpenID Connect to authenticate workflows to a cloud provider? (select two)
⬜ They don’t need to store long-lived cloud credentials as GitHub secrets.
⬜ The cloud provider issues an access token that’s valid for a single job.
⬜ OIDC lets workflows skip any trust configuration in the cloud provider.
⬜ OIDC tokens give write access to all repositories in the organization.
⬜ OIDC removes the need for the permissions key in workflows.
What permission must a job grant to request an OIDC token from GitHub?
⬜ id-token: write
⬜ contents: write
⬜ actions: write
⬜ secrets: read
An enterprise wants OIDC tokens from a unique issuer URL so that only its repositories can authenticate to its cloud resources. What should it configure?
⬜ Turn on include_enterprise_slug through the enterprise OIDC issuer customization API.
⬜ Rename the enterprise so it matches the cloud account name.
⬜ Add the enterprise slug to every workflow’s permissions block.
⬜ Use a self-hosted runner for every OIDC job.
A team configures HashiCorp Vault to trust GitHub Actions OIDC tokens. Which settings belong in the Vault configuration? (select two)
⬜ bound_issuer and oidc_discovery_url set to https://token.actions.githubusercontent.com
⬜ A JWT role with bound_claims that has at least one condition, such as the repository
⬜ A GitHub personal access token stored in Vault
⬜ The repository’s deploy key
⬜ bound_claims left empty so any repository can authenticate
A workflow sets permissions: id-token: write to read secrets from HashiCorp Vault, and its checkout step now fails. Why?
⬜ Setting permissions makes unspecified scopes default to no access, so contents: read must be added.
⬜ id-token: write revokes all other permissions permanently.
⬜ Vault blocks Git operations.
⬜ OIDC can’t be used with actions/checkout.
A team sets up OIDC from GitHub Actions to Azure so a workflow can sign in and read Azure Key Vault secrets. What is configured in Microsoft Entra ID?
⬜ An application and service principal with federated credentials that trust GitHub’s tokens
⬜ A client secret copied into a repository secret
⬜ A SAML enterprise application for GitHub Actions
⬜ A SCIM provisioning connector
A team configures OIDC between GitHub Actions and AWS. Which statements are correct? (select two)
⬜ GitHub is added as an IAM identity provider with token.actions.githubusercontent.com and audience sts.amazonaws.com.
⬜ The role’s trust policy should check token.actions.githubusercontent.com:sub to limit which repositories or branches can assume it.
⬜ An AWS access key must be stored as a GitHub secret for the OIDC exchange.
⬜ The workflow uses aws-actions/configure-aws-credentials with aws-secret-access-key.
⬜ OIDC tokens can be used without id-token: write.
An organization uses a ruleset to require a security workflow to pass before pull requests merge in all its repositories. Which statements are correct? (select two)
⬜ The workflow repository’s visibility must suit the target repositories; internal workflows can only run in internal and private repositories.
⬜ The workflow runs on pull_request, pull_request_target or merge_group, and branches or paths filters are ignored.
⬜ The workflow must be copied into each repository’s .github/workflows folder.
⬜ The rule can only be configured in individual repositories.
⬜ The workflow runs only on push events.
What are an organization’s default GitHub Actions cache settings?
⬜ Caches are kept for 7 days by default, with a default eviction limit of 10 GB per repository.
⬜ Caches are kept for 90 days, with no size limit.
⬜ Caches are kept for 400 days, with a 1 GB limit per repository.
⬜ Caches never expire, but are limited to 50 GB per organization.
Domain 5: Monitor and optimize GitHub usage (10–15%)
An enterprise owner wants audit log entries for team creation only, not every team-related event. Which search should they use?
⬜ action:team.create
⬜ action:team
⬜ operation:team
⬜ team created
Which audit log searches are valid? (select three)
⬜ created:2026-07-01..2026-07-31
⬜ -actor:Copilot
⬜ repo:"octo-org/payments"
⬜ repo:payments
⬜ org:octo-org
An investigator has a leaked token and wants every audit log action performed with it. How do they search for it?
⬜ Generate a SHA-256 hash of the token and search with hashed_token:.
⬜ Paste the raw token into the search box.
⬜ Search actor: with the token’s prefix.
⬜ Ask GitHub Support, because tokens can’t be searched.
An enterprise owner searches the audit log UI for clone activity on a repository from last week and finds nothing. Why?
⬜ Git events are left out of audit log search results; use the audit log API with include=git or streaming instead.
⬜ Clone events are only kept for 24 hours.
⬜ Git events are only recorded for public repositories.
⬜ The owner needs the security manager role to see Git events.
A team writes a script against the enterprise audit log REST API. Which statements are correct? (select three)
⬜ The token needs the read:audit_log scope.
⬜ Results use cursor-based pagination through the link header.
⬜ Each endpoint allows 1,750 queries per hour per user and IP address.
⬜ Results include events from the past two years by default.
⬜ Timestamps are returned as ISO 8601 strings in local time.
⬜ Git events are always returned unless exclude=git is set.
In GitHub Enterprise Cloud, when is a user account considered dormant?
⬜ When it hasn’t performed any qualifying activity on the enterprise in the past 30 days
⬜ When it hasn’t signed in to GitHub.com for 90 days
⬜ When it hasn’t pushed code for 180 days
⬜ When it has no Copilot seat
Which activities don’t stop a user from being counted as dormant in GitHub Enterprise Cloud? (select two)
⬜ Accessing resources only with a personal access token or SSH key
⬜ Commenting on issues
⬜ Authenticating to enterprise resources through SAML SSO
⬜ Reviewing a pull request
⬜ Starring a repository
An enterprise owner wants a list of dormant users to remove licenses they don’t need. Where do they get it in GitHub Enterprise Cloud?
⬜ From the enterprise’s Compliance page, under Reports, generating or downloading the Dormant Users report
⬜ From each organization’s Insights tab
⬜ From the enterprise audit log, filtered by action:dormant
⬜ By asking GitHub Support for a monthly export
A GitHub Enterprise Server administrator wants to free licenses held by dormant users. Which statements are correct? (select two)
⬜ Dormant users aren’t suspended automatically, but suspending them frees their licenses.
⬜ The dormancy threshold can be changed under Policies > Options in the enterprise settings.
⬜ An administrator can mark a dormant user as active to keep their license.
⬜ Site administrators are listed as dormant like other users.
⬜ The dormancy threshold is fixed at 90 days.
An enterprise reviews Copilot adoption with the Copilot usage metrics dashboard. Which statements are correct? (select two)
⬜ The dashboard shows 28-day usage trends.
⬜ Data for a day is available within two full UTC days after it ends.
⬜ Data appears in real time as developers accept suggestions.
⬜ Metrics are collected even if every user disables IDE telemetry.
⬜ The dashboard is the only way to get the data; there’s no API.
An organization owner wants a team lead to see Copilot usage metrics for the organization without making them an owner. What can they do?
⬜ Assign a custom organization role with the View organization Copilot metrics permission.
⬜ Make the team lead a billing manager.
⬜ Give the team lead admin access to one repository.
⬜ Add the team lead to the Copilot Business license.
An organization wants to find slow and unreliable workflows. Which GitHub Actions metrics should it use?
⬜ Performance metrics, which show average run times, average queue times and failure rates
⬜ Usage metrics, which show the dollar amount billed per workflow
⬜ The audit log, filtered by action:workflows
⬜ The Copilot usage metrics dashboard
Who can view organization-level GitHub Actions metrics?
⬜ Organization owners and users with the View organization Actions metrics permission
⬜ Every organization member
⬜ Only enterprise owners
⬜ Only users with the billing manager role
A billing manager requests a metered usage report for the enterprise on GitHub Enterprise Cloud. How is the report delivered?
⬜ By email to their primary address, with a download link that expires after 24 hours
⬜ As an issue in the enterprise’s .github repository
⬜ As a permanent download on the billing page
⬜ Through the audit log stream
An enterprise sets a budget for GitHub Actions usage. Which statements are correct? (select three)
⬜ The budget can be set to stop usage once its threshold is reached.
⬜ Budget alerts are sent at 75%, 90% and 100% of the amount.
⬜ Budgets can be scoped to the enterprise, an organization, a cost center or a repository.
⬜ Budgets also apply to pre-paid volume licenses.
⬜ A new budget covers usage from the start of the current billing cycle.
Without setting any budget, an enterprise gets an email that it has used 90% of its included GitHub Packages allowance. What sent it?
⬜ An included usage alert, which fires at 90% and 100% of a plan’s allowance for Actions, Packages, Git LFS and Codespaces
⬜ A budget alert created automatically for every product
⬜ A Dependabot alert
⬜ An audit log stream health check
An enterprise wants to charge each business unit for its own GitHub spending. Which statements about cost centers are correct? (select two)
⬜ License-based products such as Copilot are charged to cost centers based on the users in them.
⬜ An Azure subscription can be linked to a cost center so its usage bills to that subscription.
⬜ Cost centers work with volume and subscription billing.
⬜ Cost centers are available on GitHub Team.
⬜ Only repositories can be added to cost centers.
How many GitHub Actions minutes per month does a GitHub Enterprise Cloud plan include?
⬜ 50,000
⬜ 3,000
⬜ 2,000
⬜ Unlimited
Which GitHub Actions usage is never covered by included minutes and is always billed?
⬜ Jobs on GitHub-hosted larger runners
⬜ Jobs on self-hosted runners
⬜ Jobs on standard GitHub-hosted runners in public repositories
⬜ Jobs on standard Linux runners in private repositories
An organization deletes large old artifacts halfway through the month to cut its storage bill. What effect does this have?
⬜ It stops future storage charges, but charges already accrued this month stay.
⬜ It refunds all storage charges for the month.
⬜ It has no effect until the next billing year.
⬜ It also deletes the matching logs and caches.
Which statements about GitHub Packages billing on GitHub Enterprise Cloud are correct? (select two)
⬜ Usage for public packages is free.
⬜ Packages storage is shared with GitHub Actions artifacts.
⬜ Downloads by workflows using GITHUB_TOKEN count against the repository’s data transfer.
⬜ Storage is billed as a flat monthly fee regardless of usage.
⬜ Packages has no included storage on GitHub Enterprise Cloud.
How is GitHub Codespaces usage billed when an organization pays for its members’ codespaces?
⬜ Compute in core-hours while a codespace is active, plus storage in GB-months while it exists
⬜ A fixed monthly fee per user
⬜ Only for storage, because compute is free for organizations
⬜ Through the organization’s GitHub Actions minutes only
An organization pays for codespaces and wants to cut compute spending from codespaces left open. What can an owner do?
⬜ Set a maximum idle timeout for codespaces owned by the organization.
⬜ Turn off the default 30-minute idle timeout.
⬜ Make codespaces bill to the organization’s Actions minutes.
⬜ Limit idle timeouts for codespaces that members pay for themselves.
An organization on GitHub Enterprise Cloud uses Git LFS heavily. Which statements about its LFS billing are correct? (select two)
⬜ The plan includes 250 GiB of LFS storage and 250 GiB of bandwidth.
⬜ Downloads of source archives that include LFS objects count toward bandwidth.
⬜ Uploads of LFS files count toward bandwidth.
⬜ LFS is billed through pre-paid data packs.
⬜ Downloads by GitHub Actions don’t count toward bandwidth.
An enterprise relies on organization dependency insights to analyze open source dependencies across its organizations. What should it know?
⬜ Dependency insights is in maintenance mode, and GitHub recommends the GitHub SBOM Toolkit for organization-wide analysis.
⬜ It shows private dependencies as well as open source ones.
⬜ It works without the dependency graph.
⬜ It’s the only source of license data on GHE.com.
An enterprise owner wants GitHub Support to explain line by line why the month’s Copilot metered charges were higher than expected. What should they know?
⬜ GitHub Support generally treats Copilot usage consumption and metered billing explanations as out of scope, so the owner should analyze the usage reports themselves.
⬜ Only Premium Plus customers can open billing tickets.
⬜ Support must be contacted by phone for billing questions.
⬜ Billing questions must be posted in the GitHub Community forum.
A contributor creates a codespace from their fork of an organization’s repository. The organization pays for codespaces on its own repositories. Who is billed?
⬜ The contributor’s personal account, unless the upstream organization has allowed them to use codespaces at its expense
⬜ Always the upstream organization
⬜ Nobody, because codespaces created from forks are free
⬜ The enterprise’s default cost center
Take all 200 questions as a timed online practice exam, free:-
Related Certification Exams
- GitHub Advanced Security (GH-500) Exam Questions — the security suites in depth: Secret Protection, supply chain security, Code Security and security campaigns
- GitHub Actions (GH-200) Exam Questions — workflows, actions and runners in depth, beyond the Actions administration covered here
- GitHub Foundations (GH-900) Exam Questions — Git and GitHub basics, a good starting point before GH-100
- GitHub Copilot (GH-300) Exam Questions — Copilot features, policies and administration



