Skip to content

Configure and use secret scanning Questions

Practice questions for Configure and use secret scanning topic in GitHub Advanced Security. 29 questions covering this domain.

29 questions8 easy13 medium8 hard
Q1
medium

If a contributor bypasses repository push protection and chooses `I'll fix it later`, what alert state does GitHub create?

Q2
easy

For which repository type does secret scanning run automatically for free?

Q3
medium

Which activity can repository push protection block when a supported secret is detected?

Q4
hard

A repository administrator defines a custom secret pattern and wants push protection to use it immediately. What must happen first?

Q5
easy

Which statement about secret scanning scope is correct?

Q6
medium

Which statement correctly describes push protection for users?

Q7
hard

An organization owner wants to test a new organization-level custom pattern without creating alerts across the whole organization. What dry-run scope ...

Q8
easy

Which set lists the validity check states GitHub can show for a secret scanning alert?

Q9
hard

A repository adds 1400 entries to paths-ignore in .github/secret_scanning.yml and also tries to exclude a 2 MB generated file from push protection. Wh...

Q10
easy

What happens when GitHub detects a partner secret in a repository?

Q11
medium

Which detail is available to reviewers when they inspect a delegated bypass request?

Q12
medium

A token owner rotated a leaked credential and wants GitHub to verify the latest status of the alert now. What should the maintainer do?

Q13
hard

An organization runs a historical secret scan on one of its repositories. When the scan finishes with no secrets found, who is notified?

Q14
medium

How long does a delegated bypass request for push protection remain available before it expires?

Q15
hard

Which statement accurately describes generic secret alerts?

Q16
medium

A maintainer rotated a supported secret after an alert was created and wants GitHub to check the latest status immediately. Which action should they u...

Q17
easy

A contributor drags a file into the GitHub web UI for a public repository and GitHub blocks the upload because a supported token was found. Which cont...

Q18
medium

A delegated bypass request for push protection has been waiting for review for eight days. What is its status?

Q19
medium

A repository adds 1200 entries under paths-ignore in .github/secret_scanning.yml and expects push protection to inspect a generated file that is 2 MB ...

Q20
easy

GitHub detects a supported partner secret in a public repository. What happens next?

Sign in to see all 29 questions

Create a free account to browse all questions — completely free during our launch phase.