
GitHubActions Certification
Domain 5Objective 1
Implement Security Best Practices GH-200 Practice Questions (Page 1)
Part of the Secure and optimize automation domain, which accounts for 10-15% of the GH-200 exam.
26questions here
6free pages
10concepts
10-15%of the exam
Questions 1–5
- 1
What is the primary purpose of applying least-privilege permissions to a GitHub Actions workflow?
Select an answer first - 2
Why are long-lived Personal Access Tokens (PATs) considered a security risk in GitHub Actions workflows?
Select an answer first - 3
A workflow needs to authenticate to AWS to deploy infrastructure. Currently, it uses long-lived AWS access keys stored as secrets. You want to eliminate these long-lived secrets and use OIDC instead. What should you do?
Select an answer first - 4
Your team uses a GitHub Actions workflow to deploy a critical application to production. You need to ensure that only senior engineers can trigger the deployment job and that the deployment job has the minimum permissions required. The workflow currently uses the default GITHUB_TOKEN permissions. What should you do?
Select an answer first - 5
What is the purpose of requiring review for unverified actions in an organization's action policy?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GitHub. “GH-200” is a trademark of its owner, used for identification only.