Skip to content

GH-100 Practice Questions

Prepare for GH-100 with more than an answer.

268 questions in the full set17 sample questionsUpdated Jan 25, 2026
Exam fee
$165 USD
Level
Intermediate
Valid for
2 years
Domains covered on the exam 7
  1. Support GitHub Enterprise for users and key stakeholders15%
  2. Manage user identities and GitHub authentication20%
  3. Describe how GitHub is deployed, distributed, and licensed5%
  4. Manage access and permissions based on membership20%
  5. Enable secure software development and ensure compliance15%
  6. Manage GitHub Actions20%
  7. Manage GitHub Packages5%
  1. 1

    Which THREE of the following accurately describe how the SCIM protocol enhances user management in GitHub Enterprise Cloud? (Choose three.) A.SCIM synchronizes changes to user attributes from the identity provider to GitHub.B.SCIM deactivates GitHub accounts when users are deleted from the identity provider.C.SCIM automatically deletes organization repositories when administrators are removed.D.SCIM automates user provisioning when new users are added to the identity provider.E.SCIM generates authentication tokens for accessing GitHub's REST API.F.SCIM configures repository permissions based on user roles within the organization.

    Show answer details

    Correct answer: A, B, D

  2. 2

    When comparing a partner identity provider integration with a non-partner identity management solution for GitHub Enterprise Managed Users, which statement is Correct? A.The non-partner identity provider integrations can utilize OIDC for authentication.B.The non-partner identity provider integrations require manual configuration of SAML 2.0 details.C.The partner identity provider integrations support fewer GitHub-supported authentication methods.D.The partner identity provider integrations rely on the partner to support the application on the partner IdP.

    Show answer details

    Correct answer: B

  3. 3

    You are the GitHub Enterprise Administrator for Contoso, Ltd. The company operates a GitHub Enterprise Server (GHES) instance in a high-availability configuration. You notice that the primary appliance is experiencing unusually high CPU load, causing performance degradation for users. You need to investigate the specific processes consuming resources before deciding on a course of action.

    Which command should you execute via SSH to generate a detailed diagnostics report specifically for this performance analysis?

    Show answer details

    Correct answer: D

    The ghe-top command provides a real-time view of running processes and resource usage, similar to the standard Linux top command but tailored for GHES services. This is the best tool for immediate investigation of high CPU load. ghe-support-bundle collects logs for support tickets but is not a real-time monitoring tool.

  4. 4

    A development team at Fabrikam uses GitHub Enterprise Cloud. They want to integrate a third-party project management tool that requires read-only access to repository metadata and issues across three specific repositories. The integration should not be tied to any specific user account to ensure continuity if staff changes.

    Which integration method should you recommend?

    Show answer details

    Correct answer: B

    GitHub Apps are the preferred integration method for machine-to-machine communication. They act on their own behalf (not masquerading as a user), offer granular permissions (read-only access to issues/metadata), and can be installed on specific repositories. OAuth Apps act as a user and have broader scopes.

  5. 5

    You are troubleshooting a SAML Single Sign-On (SSO) issue where a specific user is unable to authenticate to your GitHub Enterprise Cloud organization. The user receives a '403 Forbidden' error immediately after successfully logging in at the Identity Provider (IdP).

    Review the following diagram of the SAML flow. At which step is the failure most likely occurring?

    Show answer details

    Correct answer: A

    If the user authenticates successfully at the IdP but gets a 403 from GitHub, the issue is likely in Step 4, where GitHub validates the SAML response. This often indicates a NameID mismatch, signature verification failure, or that the user's SAML identity is already linked to a different GitHub account.

    sequenceDiagram participant User participant GitHub as Service Provider (SP) participant IdP as Identity Provider User->>GitHub: 1. Attempts access GitHub->>IdP: 2. Redirects (SAML Request) User->>IdP: 3. Enters Credentials IdP->>GitHub: 4. Sends SAML Response (Assertion) GitHub->>User: 5. Grants/Denies Access

  6. 6

    A GitHub Actions workflow is failing with an error indicating that a self-hosted runner with the label windows-gpu-large is not available. The administrator confirms that several runners with this label are online and idle. The workflow is running in a private repository. What is the most likely configuration issue preventing the workflow from using the available runners?

    graph TD subgraph GitHub Enterprise Cloud Org[Organization] Repo[Private Repo] Workflow[Workflow Job runs-on: windows-gpu-large] end subgraph On-Premises Network RunnerGroup[Runner Group: 'GPU-Runners'] Runner1[Runner 1 (windows-gpu-large)] Runner2[Runner 2 (windows-gpu-large)] end Workflow -- Needs --> Runner1 Org -- Contains --> Repo RunnerGroup -- Contains --> Runner1 RunnerGroup -- Contains --> Runner2 Repo -- ??? --> RunnerGroup
    Show answer details

    Correct answer: A

    Self-hosted runners are managed in groups, and these groups must be explicitly configured to be accessible by specific repositories or all repositories in an organization. Even if the runners are online and have the correct label, if the runner group is not authorized for the repository where the workflow is running, the job will not be assigned to them.

  7. 7

    Your organization uses a fork-and-pull workflow for contributions to a central, open-source repository. To maintain code quality, you have a requirement that every pull request must be reviewed and approved by at least two members of the 'Core-Maintainers' team before it can be merged. How should you enforce this requirement?

    Show answer details

    Correct answer: B

    Branch protection rules are the correct mechanism for enforcing conditions before a branch can be merged. You can configure a rule for the main branch to 'Require pull request reviews before merging' and set the 'Required number of approvals' to 2. You can also specify that these reviews must come from Code Owners to link it to the specific team.

  8. 8

    You have a GitHub Enterprise Server instance and need to configure backups. According to GitHub's best practices, where should the backup data be stored?

    Show answer details

    Correct answer: D

    The recommended practice is to use ghe-backup to send data to a separate host (the backup host). This ensures that a failure of the primary GHES appliance does not affect the backup data. While offsite backups are also recommended, the primary backup location should be a separate host.

Create an account to continue.