GitHub Foundations (GH-900) · Domain 6 · 13% of exam

Understand privacy, security, and administration

Drill 20 practice questions focused entirely on Understand privacy, security, and administration for the GitHub GH-900 exam. Tap an answer for instant feedback and a full explanation — no sign-up, always free.

Verified answer20 questions
Question 1 of 20

Your team's CI pipeline occasionally fails, but developers have been merging pull requests into the main branch anyway, breaking the deployment. As a repository admin, which branch protection rule setting should you enable to prevent pull requests from being merged until all CI tests pass?

Reviewed for accuracy · Report an issue
Question 2 of 20

Your company has adopted Enterprise Managed Users (EMUs) for its GitHub Enterprise Cloud account. A developer on your team complains that although they can sign in with their managed account, they are unable to open a pull request on a well-known open-source project hosted outside your enterprise. What is the most accurate explanation for this behavior?

Reviewed for accuracy · Report an issue
Question 3 of 20

A financial services company must ensure that every developer's GitHub identity is centrally created and fully controlled by the company's identity provider (IdP), with no ability for developers to use personal GitHub accounts or invite outside collaborators. Which GitHub offering is specifically designed to meet this requirement?

Reviewed for accuracy · Report an issue
Question 4 of 20

You are an organization owner at a company that just experienced a phishing incident. Leadership wants to guarantee that every member of your GitHub organization uses two-factor authentication, and that any member who has not enabled it loses access until they comply. Which action should you take in the organization settings?

Reviewed for accuracy · Report an issue
Question 5 of 20

A contractor who is not a member of your organization needs to contribute code to exactly one private repository for a short-term project. As the organization owner, you want to give them access to that single repository without adding them to the organization or any teams. What is the most appropriate way to grant this access?

Reviewed for accuracy · Report an issue
Question 6 of 20

A platform engineering team at a large enterprise builds a shared logging library that every internal development team should be able to view and reuse. The company uses GitHub Enterprise Cloud with several organizations under one enterprise account. The team wants any authenticated enterprise member to read the repository, but they do not want it exposed to the general public on the internet. Which repository visibility setting should they choose?

Reviewed for accuracy · Report an issue
Question 7 of 20

You are an organization owner rolling out GitHub Copilot Business to your development team. Company policy states that Copilot must not return suggestions that match publicly available code, to reduce licensing risk. Where do you configure this restriction so it applies to every member using Copilot in the organization?

Reviewed for accuracy · Report an issue
Question 8 of 20

You are an organization owner on GitHub Enterprise Cloud with a Copilot Business subscription. Your compliance team wants to allow Copilot code completions for all members but keep the Copilot Chat feature turned off org-wide until a review is complete. Where do you configure this restriction?

Reviewed for accuracy · Report an issue
Question 9 of 20

You are an organization owner at a company that just purchased Copilot Business seats for all developers. Leadership wants to ensure that certain Copilot features are governed consistently across every member of the organization, rather than each developer configuring their own preferences. Where should you go to enforce these settings for the whole organization?

Reviewed for accuracy · Report an issue
Question 10 of 20

You are a member of an organization on GitHub and need to update the organization's billing payment method after a company credit card change. When you navigate to the billing settings, you find you cannot access them. A colleague suggests your role is the issue. Which organization role must you hold to manage billing settings and other organization-wide administrative options?

Reviewed for accuracy · Report an issue
Question 11 of 20

You are an organization owner. A contractor needs to review and approve pull requests and push to feature branches on one repository, but must not be able to change repository settings, manage webhooks, or delete the repository. Which repository-level role should you grant to follow least privilege?

Reviewed for accuracy · Report an issue
Question 12 of 20

An organization owner wants a senior developer to be able to add and remove members from a specific team, edit that team's description, and manage the team's repository access—without granting them full organization-wide administrative control. Which approach follows the principle of least privilege?

Reviewed for accuracy · Report an issue
Question 13 of 20

A developer at your company is concerned about phishing attacks that trick users into entering their GitHub password and one-time codes on fake login pages. They want a sign-in method that removes the password entirely and is resistant to these phishing attempts. Which GitHub account security option should they enable?

Reviewed for accuracy · Report an issue
Question 14 of 20

You maintain a shared repository where several developers push directly to the main branch, occasionally introducing unreviewed changes that break the build. As a repository maintenance best practice, what should you configure to ensure all changes to main are reviewed before merging?

Reviewed for accuracy · Report an issue
Question 15 of 20

A developer at your company enabled two-factor authentication (2FA) on their GitHub account using an authenticator app on their phone. Their phone was lost and they can no longer generate time-based codes. They did not configure a security key or SMS fallback. What is the intended way for them to regain access to their account?

Reviewed for accuracy · Report an issue
Question 16 of 20

You manage an organization repository and want a community volunteer to help triage issues and pull requests—labeling, closing, reopening, and assigning them—but you do NOT want this person to be able to push code to the repository. Which repository role should you assign?

Reviewed for accuracy · Report an issue
Question 17 of 20

A startup published an internal utility as a public repository by mistake. The engineering lead asks you to change the repository's visibility to private immediately. After you make the change, which statement correctly describes the effect on people who had previously starred or forked the public repository?

Reviewed for accuracy · Report an issue
Question 18 of 20

You work at a company using GitHub Enterprise Cloud with a single organization. Your team is building an internal shared library that every employee across all teams in the organization should be able to view and use, but it must never be visible to anyone outside the company. Which repository visibility setting best meets this requirement?

Reviewed for accuracy · Report an issue
Question 19 of 20

A developer at your company needs to push commits directly to a repository, create branches, and merge approved pull requests. However, company policy states that only team leads should be able to change repository settings, manage collaborator access, or delete the repository. Which repository role should you assign to this developer to follow the principle of least privilege?

Reviewed for accuracy · Report an issue
Question 20 of 20

You maintain a public repository and want to see a single dashboard summarizing security-related information such as open Dependabot alerts, code scanning results, and secret scanning findings. Which area of the repository should you open to review this consolidated view?

Reviewed for accuracy · Report an issue

More GH-900 practice

Keep going with the other GitHub Foundations (GH-900) domains, or take a full timed mock exam.

← Back to GH-900 overview