GH-200 sample questions with answers
10 free GH-200 sample questions across the exam's domains, each with its answer and an explanation. No account needed.
GH-200 sample questions
GitHub Actions (GH-200), GitHub / Microsoft.
Question 4
Domain: Consume and troubleshoot workflows
Workflow templates are stored in an organization's internal .github repository. In which repositories can members use them?
- All repositories in the organization, including public ones
- Private repositories only
- Internal and private repositories only
- Only the .github repository itself
Show the answer
Answer: C. Internal and private repositories only
Templates are available to repositories with the same or more restricted visibility than the template repository: a public .github repository serves all types, an internal one serves internal and private repositories, and a private one serves private repositories only.
Checked against: https://docs.github.com/en/actions/reference/workflows-and-actions/reusing-workflow-configurations#workflow-template-availability
Question 5
Domain: Consume and troubleshoot workflows
A step fails with an unhelpful message and you want the extra debug output that actions and the runner emit for each step.
What should you set before re-running?
- A secret or variable named ACTIONS_STEP_DEBUG with the value true
- A secret or variable named ACTIONS_RUNNER_DEBUG with the value true
- The job key debug: true under the failing job
- An environment variable RUNNER_LOG_LEVEL=trace in the workflow
Show the answer
Answer: A. A secret or variable named ACTIONS_STEP_DEBUG with the value true
ACTIONS_STEP_DEBUG enables step debug logging, which shows ::debug:: output and extra detail in the step logs; ticking "Enable debug logging" when re-running turns on debug logging for just that attempt. ACTIONS_RUNNER_DEBUG instead produces runner diagnostic logs that are added to the downloadable log archive.
Checked against: https://docs.github.com/en/actions/how-tos/monitor-workflows/enable-debug-logging
Question 8
Domain: Manage GitHub Actions for the enterprise
The platform team wants a central security-scan workflow to run and pass on pull requests in all of the organization's repositories before merging, without copying the file into each repository.
Which feature provides this?
- A workflow template in the .github repository marked as mandatory
- A branch protection rule in each repository listing the template name
- An organization ruleset with the "Require workflows to pass before merging" rule
- An organization secret that triggers the workflow on every pull request
Show the answer
Answer: C. An organization ruleset with the "Require workflows to pass before merging" rule
Rulesets can require a workflow from a central repository to run and pass before merging, targeted at many repositories at once. Templates are only copied when someone chooses them and cannot be made mandatory, and secrets do not trigger workflows.
Question 9
Domain: Manage GitHub Actions for the enterprise
A workflow in private repository app-a calls octo-org/shared-ci/.github/workflows/test.yml@v1. shared-ci is also private in the same organization. Runs fail because the called workflow cannot be accessed.
What must be configured?
- Grant app-a's GITHUB_TOKEN contents: read on shared-ci with a permissions block
- In shared-ci's Actions settings, set Access to allow repositories in the organization
- Add secrets: inherit to the calling job so it can read shared-ci
- Make shared-ci a template repository so its workflows become reusable
Show the answer
Answer: B. In shared-ci's Actions settings, set Access to allow repositories in the organization
Reusable workflows in a private repository can be called by other repositories only when the Access policy in that repository's Actions settings explicitly allows it. The permissions key cannot grant access to another repository, and secrets or template status do not affect workflow access.
Checked against: https://docs.github.com/en/actions/reference/workflows-and-actions/reusing-workflow-configurations#access-to-reusable-workflows
Question 10
Domain: Secure and optimize automation
A deployment job must exchange a GitHub OIDC token for short-lived cloud credentials instead of using long-lived keys stored as secrets.
Which permission must the job have to request the OIDC token?
- contents: write
- actions: write
- deployments: write
- id-token: write
Show the answer
Answer: D. id-token: write
Requesting the OIDC JSON Web Token requires id-token: write; it does not give write access to any repository resource. The other scopes control repository contents, workflow runs and deployment records, and none of them allows fetching an OIDC token.
Checked against: https://docs.github.com/en/actions/concepts/security/openid-connect
More practice
A 20-question practice sampler is free with an account; Pro adds the full question bank and timed mock exams.
GH-200 course and practice exam: GitHub Actions: the exam guide, with the format, cost, pass mark and domains from the vendor.