Understand privacy, security, and administration
Drill 20 practice questions focused entirely on Understand privacy, security, and administration for the GitHub GH-900 exam. Tap an answer for instant feedback and a full explanation — no sign-up, always free.
Your team's CI pipeline occasionally fails, but developers have been merging pull requests into the main branch anyway, breaking the deployment. As a repository admin, which branch protection rule setting should you enable to prevent pull requests from being merged until all CI tests pass?
Your company has adopted Enterprise Managed Users (EMUs) for its GitHub Enterprise Cloud account. A developer on your team complains that although they can sign in with their managed account, they are unable to open a pull request on a well-known open-source project hosted outside your enterprise. What is the most accurate explanation for this behavior?
A financial services company must ensure that every developer's GitHub identity is centrally created and fully controlled by the company's identity provider (IdP), with no ability for developers to use personal GitHub accounts or invite outside collaborators. Which GitHub offering is specifically designed to meet this requirement?
You are an organization owner at a company that just experienced a phishing incident. Leadership wants to guarantee that every member of your GitHub organization uses two-factor authentication, and that any member who has not enabled it loses access until they comply. Which action should you take in the organization settings?
A contractor who is not a member of your organization needs to contribute code to exactly one private repository for a short-term project. As the organization owner, you want to give them access to that single repository without adding them to the organization or any teams. What is the most appropriate way to grant this access?
A platform engineering team at a large enterprise builds a shared logging library that every internal development team should be able to view and reuse. The company uses GitHub Enterprise Cloud with several organizations under one enterprise account. The team wants any authenticated enterprise member to read the repository, but they do not want it exposed to the general public on the internet. Which repository visibility setting should they choose?
You are an organization owner rolling out GitHub Copilot Business to your development team. Company policy states that Copilot must not return suggestions that match publicly available code, to reduce licensing risk. Where do you configure this restriction so it applies to every member using Copilot in the organization?
You are an organization owner on GitHub Enterprise Cloud with a Copilot Business subscription. Your compliance team wants to allow Copilot code completions for all members but keep the Copilot Chat feature turned off org-wide until a review is complete. Where do you configure this restriction?
You are an organization owner at a company that just purchased Copilot Business seats for all developers. Leadership wants to ensure that certain Copilot features are governed consistently across every member of the organization, rather than each developer configuring their own preferences. Where should you go to enforce these settings for the whole organization?
You are a member of an organization on GitHub and need to update the organization's billing payment method after a company credit card change. When you navigate to the billing settings, you find you cannot access them. A colleague suggests your role is the issue. Which organization role must you hold to manage billing settings and other organization-wide administrative options?
You are an organization owner. A contractor needs to review and approve pull requests and push to feature branches on one repository, but must not be able to change repository settings, manage webhooks, or delete the repository. Which repository-level role should you grant to follow least privilege?
An organization owner wants a senior developer to be able to add and remove members from a specific team, edit that team's description, and manage the team's repository access—without granting them full organization-wide administrative control. Which approach follows the principle of least privilege?
A developer at your company is concerned about phishing attacks that trick users into entering their GitHub password and one-time codes on fake login pages. They want a sign-in method that removes the password entirely and is resistant to these phishing attempts. Which GitHub account security option should they enable?
You maintain a shared repository where several developers push directly to the main branch, occasionally introducing unreviewed changes that break the build. As a repository maintenance best practice, what should you configure to ensure all changes to main are reviewed before merging?
A developer at your company enabled two-factor authentication (2FA) on their GitHub account using an authenticator app on their phone. Their phone was lost and they can no longer generate time-based codes. They did not configure a security key or SMS fallback. What is the intended way for them to regain access to their account?
You manage an organization repository and want a community volunteer to help triage issues and pull requests—labeling, closing, reopening, and assigning them—but you do NOT want this person to be able to push code to the repository. Which repository role should you assign?
A startup published an internal utility as a public repository by mistake. The engineering lead asks you to change the repository's visibility to private immediately. After you make the change, which statement correctly describes the effect on people who had previously starred or forked the public repository?
You work at a company using GitHub Enterprise Cloud with a single organization. Your team is building an internal shared library that every employee across all teams in the organization should be able to view and use, but it must never be visible to anyone outside the company. Which repository visibility setting best meets this requirement?
A developer at your company needs to push commits directly to a repository, create branches, and merge approved pull requests. However, company policy states that only team leads should be able to change repository settings, manage collaborator access, or delete the repository. Which repository role should you assign to this developer to follow the principle of least privilege?
You maintain a public repository and want to see a single dashboard summarizing security-related information such as open Dependabot alerts, code scanning results, and secret scanning findings. Which area of the repository should you open to review this consolidated view?
More GH-900 practice
Keep going with the other GitHub Foundations (GH-900) domains, or take a full timed mock exam.
← Back to GH-900 overview