Skip to content

Implement guardrails and accountability Questions

Practice questions for Implement guardrails and accountability topic in GitHub Agentic AI Developer. 24 questions covering this domain.

24 questions7 easy10 medium7 hard
Q1
hard

A repository ruleset allows only specific commit authors, and Copilot cloud agent is blocked from creating or updating pull requests. According to Git...

Q2
medium

A security team wants VS Code agents to reach only approved API domains. Which configuration approach matches the enterprise guidance?

Q3
easy

What is the first step in defining appropriate autonomy levels for agent actions according to GH-600?

Q4
medium

An enterprise wants AI features in VS Code disabled unless the signed-in GitHub account belongs to an approved organization. Which policy provides tha...

Q5
hard

An administrator wants terminal commands, fetch requests, and task execution to always require manual approval even if users enable broader auto-appro...

Q6
medium

Which control best enforces the least-privilege principle for agents?

Q7
medium

A company has hook configurations in repositories, but it wants all hook commands ignored on managed devices. Which policy should be set to false?

Q8
medium

Security wants to block extension-contributed tools while still allowing built-in tools and MCP tools. Which policy does that?

Q9
medium

Which policy should administrators disable to stop developers from turning on global tool auto-approval?

Q10
easy

Which ChatMCP policy value disables MCP server support entirely in VS Code?

Q11
hard

An organization sets ChatApprovedAccountOrganizations to [contoso]. A developer signs in with a personal GitHub account that is not in Contoso. What h...

Q12
easy

Which enterprise policy disables autonomous agents in VS Code while still allowing non-agent chat experiences such as ask or edit?

Q13
hard

A security lead assumes GitHub Copilot content exclusions will hide certain files from Copilot cloud agent. What is the correct expectation?

Q14
easy

Even after a user has access to Copilot cloud agent, who can still block it from being used in a specific repository?

Q15
medium

An enterprise wants developers to run MCP servers only from the approved registry source in VS Code. Which `ChatMCP` value enforces that?

Q16
medium

An organization wants chat agents in VS Code to keep built-in tools and MCP tools but lose browser-based web interaction. Which policy should be set t...

Q17
hard

Why do Microsoft's enterprise docs recommend agent sandboxing or dev containers when teams use auto-approval or other high-autonomy modes?

Q18
easy

How is Copilot cloud agent enabled by default across GitHub Copilot plan types?

Q19
hard

An enterprise wants VS Code to show only approved MCP servers from its private registry and not from the public GitHub MCP registry. Which policy sets...

Q20
hard

What is the effect of setting the ChatToolsAutoApprove policy to false in VS Code enterprise management?

Sign in to see all 24 questions

Create a free account to browse all questions — completely free during our launch phase.