Skip to content

Security and Administration Questions

Practice questions for Security and Administration topic in GitHub Foundations. 27 questions covering this domain.

27 questions5 easy15 medium7 hard
Q1
medium

How can an organization-wide Copilot policy help enterprise administrators?

Q2
hard

What is the primary purpose of Enterprise Managed Users (EMUs) in GitHub Enterprise Cloud?

Q3
medium

An organization admin wants a team to manage issues and pull requests without granting code push access. Which repository role is the best fit?

Q4
medium

Which repository visibility setting is intended to restrict access to explicitly authorized users rather than the general public?

Q5
medium

Which two-factor authentication methods does GitHub support for securing user accounts?

Q6
medium

What do branch protection rules allow repository administrators to enforce?

Q7
medium

For personal use of the GitHub REST API, which credential does GitHub recommend creating when possible?

Q8
hard

A security team wants to use an SSH key with resources owned by an organization that enforces SAML single sign-on. What extra step is required?

Q9
hard

A company uses SAML single sign-on for an organization. A developer already has a personal access token but still cannot use it against that organizat...

Q10
easy

What is true about a passkey on GitHub?

Q11
medium

What is the main limitation of GITHUB_TOKEN in a GitHub Actions workflow by default in this context?

Q12
hard

An organization wants an integration to access the API on behalf of users or the organization with more controlled permissions. What does GitHub recom...

Q13
medium

A developer uses Git over HTTPS to GitHub from the command line. What should they enter when Git prompts for a password?

Q14
medium

A maintainer needs to discuss and fix a security vulnerability in a public repository before publicly alerting users. Which feature supports that work...

Q15
medium

Before merging a pull request that changes dependencies, which feature helps you review the impact and spot vulnerable versions?

Q16
easy

Which GitHub feature blocks a push when hardcoded credentials are detected?

Q17
medium

An organization wants a high-level view of security trends, risky repositories, and overall security status. Which feature should it use?

Q18
easy

Which feature alerts you to vulnerable dependencies and can create pull requests to update them?

Q19
hard

On GitHub Free, GitHub Pro, or GitHub Team, when are artifact attestations available?

Q20
medium

Which feature automatically detects security vulnerabilities and coding errors in new or modified code so you can fix them before merge?

Sign in to see all 27 questions

Create a free account to browse all questions — completely free during our launch phase.