01. Which two pieces of information are included in your organization's log?
(Select only one answer.)
a) The user that performed the action and the date and time of the action.
b) The user affected by the action and your enterprise's license consumption.
c) The date and time of the action and the code diff it produced.
d) The repository an action was performed in and its open Dependabot alert count.
Leadership has asked for the written list it was promised. Which of Tailspin's current practices belong on that list?
(Select all that apply.)
a) Publishing the routing SDK from a public repository owned by the enterprise
b) Authenticating a clone of an enterprise repository over HTTPS with a personal access token
c) Signing in with the personal GitHub.com accounts the engineers created for themselves
d) Forking the upstream open-source libraries in order to send fixes back to them
e) Running Actions workflows in the repositories that move across into wwi-retail
03. You're an admin and want to enable team synchronization for your organization. What installation permissions do you need to configure team synchronization for Microsoft Entra ID?
(Select only one answer.)
a) Provide the tenant URL
b) Read all users' full profiles
c) Enable SAML Single Sign-on (SSO)
d) Generate a valid Single Sign-on for Web Systems (SSWS) token
The platform team is replacing the per-repository configuration in relecloud-payments before the audit. Which actions together satisfy the merge requirements for that organization, including the on-call incident team's need?
(Select all that apply.)
a) Give the on-call incident team the admin role on every payments repository, so they can review, approve and merge during an outage.
b) Copy the branch protection settings and required reviews from the strictest payments repository into all the others.
c) In that ruleset, require a pull request with two approving reviews and a review from a code owner, and block force pushes.
d) Add the on-call incident team to the bypass list on that ruleset.
e) Create a ruleset in the relecloud-payments organization and set its repository targeting to cover every repository the organization owns.
05. Suppose you created a bug fix on a new branch and want it to become part of the next production build generated from the main branch. What should you do next?
(Select only one answer.)
a) Create a pull request to merge your new branch into the main branch.
b) Commit your changes directly to the main branch.
c) Tag the tip of your branch with a release version so the production build includes the fix.
d) Create a new branch from the main branch and copy your changes to the new branch.
06. As an organization owner, you want to ensure that everyone who is signed in to your corporate network can access the GitHub website without requiring a second sign-in. Which technology would you enable to accomplish this?
(Select only one answer.)
a) Two-factor authentication
b) SSH keys
c) Single sign-on
d) Personal Access Tokens
07. You want to grant a user the permissions required to add and remove organization members to and from a team. Which permission would you need to grant that user?
(Select only one answer.)
a) The admin permission on a repository
b) Team maintainer
c) Organization billing manager
d) The maintain permission on a repository
Security has ruled that no personal access token may reach Fabrikam's organization-owned resources until an organization owner has reviewed it, that the classic tokens must be shut out of the organization, and that internal automation has to keep running. Which actions satisfy that ruling?
(Select all that apply.)
a) Set the organization's separate policy for personal access tokens (classic) so that they cannot reach organization-owned resources
b) Re-create the internal automation as GitHub Apps installed on the repositories it serves
c) Lower the organization's base permissions to Read so that tokens inherit no more than read access to its repositories
d) Rotate the existing tokens on a schedule and log each rotation
e) Set the organization's fine-grained token policy to require administrator approval before a token can reach it
09. What is the best way to report a bug to a GitHub project?
(Select only one answer.)
a) Search for the bug in the project's existing issues, and create a new one if it hasn't been reported yet.
b) Email the project owner directly with a description of what went wrong.
c) Create a detailed issue report with the steps to reproduce the bug and the version you were running.
d) Open a discussion in the repository describing what went wrong, and ask other users whether they have seen the same behavior.
The platform team is working out how to give the risk team what it needs on the tailwind-retail repositories. Which approach fits the constraint it has been given?
a) Add the risk team as outside collaborators carrying Triage access on each retail repository, so that their reach stops at exactly the repositories they have been named on
b) Ask an organization owner to review and dismiss each alert on the risk team's behalf, on the basis that alert dismissal cannot be delegated to any role below organization owner
c) Grant the risk team the Write role on the retail repositories, since dismissing an alert is a write action, and ask the team in writing not to push to any of them
d) Create a custom repository role that inherits Read and adds the permission to dismiss or reopen Dependabot alerts, then grant the risk team that role