Limited-Time Offer: Enjoy 50% Savings! Ends in 00h 00m 00s Coupon code: 50OFF
Skip to content

Free Microsoft GitHub Administration GH-100 Exam Questions

Page: 1 / 7 Total 65 questions

Want more questions? Get Premium Access.

Question 1

In a GitHub repository using Dependabot, which of the following best describes the purpose of the .github/dependabot.yml file?

Correct Answer: A. It configures scheduling, package ecosystems, and target directories for update checks.
Explanation:

The .github/dependabot.yml file defines Dependabot's package-ecosystem, the directories to inspect, and the update schedule (daily/weekly/monthly), controlling when and where Dependabot checks for new versions.


Question 2

Your organization wants to reduce costs. Which of the following actions should you take?

Correct Answer: C. Regularly audit for inactive users
Explanation:

Regularly auditing for inactive (dormant) users lets you suspend or remove accounts that aren't consuming seats - freeing up licenses and directly lowering your per-user subscription costs.


Question 3

Which GitHub feature is responsible for tracking dependencies and known vulnerabilities in those dependencies from an advisory database?

Correct Answer: B. Dependency Graph
Explanation:

The DependencyGraph continuously analyzes your repository's manifest and lock files to build an inventory of direct and transitive dependencies and flags any that match entries in the GitHub Advisory Database, surfacing known vulnerabilities.


Question 4

You need to contact GitHub Premium Support. What are valid reasons for submitting a support ticket? (Each answer presents a complete solution. Choose two.)

Correct Answer: C. business impact from security issues within your organization; D. outages on GitHub.com affecting core Git functionality
Explanation:

Business-impact security issues (for example, a critical vulnerability affecting your organization) are classified as High-priority tickets and are covered under your Premium Support SLA.

Outages on GitHub.com that disrupt core Git or web application functionality trigger Urgent-priority responses under Premium Support's SLA.


Question 5

Which of the following are valid ways to pass data to a reusable workflow in a separate repository?

Correct Answer: B. Define inputs in the reusable workflow and pass values from the calling workflow.; C. Define the secrets in the caller repository and call the reusable workflow using the 'secrets' keyword.
Explanation:

You declare namedinputs in the reusable workflow's on.workflow_call block and then pass values from the caller using thewithkeyword, allowing the called workflow to consume those parameters.

You define required secrets in the caller repository and supply them to the reusable workflow via thesecretskeyword in the workflow-call step, ensuring sensitive values are securely passed.


Question 6

What will happen if Dependabot discovers a vulnerable transitive dependency in a repository?

Correct Answer: A. It creates a pull request to update the direct dependency to a version that resolves the vulnerability.
Explanation:

Dependabot will automatically open a pull request that updates the direct dependency to a version which, in turn, resolves (or removes) the vulnerable transitive dependency---ensuring the fix is applied via your declared dependencies.


Question 7

You want to ensure a secret is automatically available to only workflows in internal and private repositories in the organization. Where do you configure the required access policy?

Correct Answer: D. Organization secret
Explanation:

You set the access policy on the Organization Secret itself - configuring its visibility so it's scoped automatically to only internal and private repositories.


Question 8

You are planning GitHub account management for a healthcare organization with strict compliance requirements. Which THREE of the following statements accurately describe GitHub Enterprise Managed Users (EMU) accounts? (Choose three.)

Correct Answer: B. EMU accounts are managed through an identity provider such as Azure AD.; D. EMU accounts restrict users to enterprise-related activities only; F. EMU accounts are owned by the organization and cannot be unlinked.
Explanation:

Enterprise Managed User accounts are provisioned and authenticated exclusively through your identity provider (for example, AzureAD), so the IdP handles their creation, attribute updates, and deprovisioning.

Managed user accounts cannot create public content or interact with repositories outside your enterprise; they're confined to private and internal repos within the enterprise.

EMU accounts are owned and controlled by the enterprise (via the IdP) and cannot be converted into or unlinked as personal accounts outside that enterprise.


Question 9

What needs to be done to ensure that only specific repositories can access the runners in an organization runner group?

Correct Answer: C. Configure repository access in the runner group settings.
Explanation:

In the organization's runner group settings, switch the access from ''All repositories'' to ''Selected repositories'' and then explicitly choose which repos may use those runners.


Question 10

When a token is used to perform actions across different GitHub resources, how is this reflected in audit logs?

Correct Answer: A. Each API action made with the token generates a separate audit log entry
Explanation:

Each API call authenticated with a token generates its own audit-log event, so you'll see a distinct entry for every action performed across different resources, each annotated with the token's hashed ID, actor, and source IP.