Microsoft GH-100 Practice Exam Questions & Answers
5 Free Questions
· Last reviewed: September 12, 2026
· Prepared & Reviewed by the ValidExamDumps Editorial Team
Exam Facts
Microsoft GH-100 Exam Details
Key details for this exam, checked against the published exam outline
65
Practice Questions (Our Bank)
100 minutes
Exam Duration
700 out of 1000
Passing Score
USD 165
Exam Fee (United States)
- Exam Code
- GH-100
- Full Name
- GitHub Administration
- Issuing Body
- Microsoft
- Question Format (Our Bank)
- Multiple Choice
- Delivery
- Online proctored exam or at a testing center through Pearson VUE
- Eligibility
- No prerequisites required
Practice Questions
Free GH-100 Practice Questions
Each question shows the correct answer and an explanation of why it is right
VA
ValidExamDumps Editorial Team
Every question and its answer is checked by our GH-100 exam
preparation team, who also write the explanation shown with each one.
How we research and review these pages
When comparing a partner identity provider integration with a non-partner identity management solution for GitHub Enterprise Managed Users, which statement is Correct?
Correct Answer:
B
Explanation
Non-partner identity provider integrations require you to enter SAML2.0 configuration details by hand - such as the Sign-on URL, Issuer, and X.509 certificate - whereas partner IdPs supply a pre-configured application integration.
You need to contact GitHub Premium Support. What are valid reasons for submitting a support ticket? (Each answer presents a complete solution. Choose two.)
Correct Answer:
C, D
Explanation
Business-impact security issues (for example, a critical vulnerability affecting your organization) are classified as High-priority tickets and are covered under your Premium Support SLA.
Outages on GitHub.com that disrupt core Git or web application functionality trigger Urgent-priority responses under Premium Support's SLA.
What makes GitHub Apps a more secure choice for automation over OAuth Apps?
Correct Answer:
D
Explanation
GitHub Apps authenticate as themselves with fine-grained, installation-scoped permissions and short-lived tokens - rather than inheriting a user's broad OAuth scopes - minimizing blast radius and aligning with least-privilege principles.
A team member is unable to push to a repository due to a 403-error related to branch protection. What should the GitHub Enterprise administrator do first?
Correct Answer:
B
Explanation
The administrator should first review the user's repository role and the branch protection rules applied to that branch. A 403 error on push almost always indicates that the user either lacks the necessary write permissions or is not listed among the actors authorized by the branch protection settings.
Which GitHub feature is responsible for tracking dependencies and known vulnerabilities in those dependencies from an advisory database?
Correct Answer:
B
Explanation
The DependencyGraph continuously analyzes your repository's manifest and lock files to build an inventory of direct and transitive dependencies and flags any that match entries in the GitHub Advisory Database, surfacing known vulnerabilities.
Domain 1: Manage GitHub identities and access
15% - 20%
This domain covers user identity management, authentication methods, and access control configuration. You need to work with managed users, personal accounts, SAML SSO, 2FA, SCIM synchronization, and identity provider selection to secure your GitHub environment.
Sample questions from this domain above:
Q3Q4
Domain 2: Administer GitHub Enterprise environment
10% - 15%
This domain focuses on supporting enterprise users, managing deployment scenarios, and licensing. You should understand different GitHub Enterprise configurations, be able to generate support bundles, and recommend development process standards for your organization.
Domain 3: Implement secure software development and compliance
25% - 30%
This is the heaviest weighted domain, covering security policies, repository features, and API access. You must configure vulnerability management, secret scanning, CodeQL, and audit logging while managing integrations and personal access tokens.
Sample questions from this domain above:
Q2Q5
Domain 4: Manage GitHub Actions
20% - 25%
This domain addresses workflow configuration, runner management, and secrets. You need to manage both GitHub-hosted and self-hosted runners, apply organizational policies, configure IP allow lists, and handle encrypted secrets at different scope levels.
Sample question from this domain above:
Q1
Domain 5: Monitor and optimize GitHub usage
10% - 15%
This domain involves analyzing enterprise activity and optimizing costs. You should be comfortable interpreting audit logs, distinguishing between admin and support responsibilities, evaluating usage patterns, and recommending optimization strategies.
FAQ
GH-100 Exam FAQ
Common questions about the exam itself
Is GH-100 suitable for someone new to GitHub administration or do I need hands-on experience first?
GH-100 targets professionals with intermediate experience managing GitHub environments, typically 6 to 12 months hands-on at the organization or enterprise level. This is not an entry-level exam. New administrators should first gain practical experience with repositories, access control, and organizational configuration before attempting it.
What is the biggest challenge area in GH-100 and how should I prepare for it?
The secure software development and compliance domain makes up 25 to 30 percent of the exam, making it the heaviest weighted section. This covers vulnerability management, secret scanning, CodeQL, audit logging, and API access. Dedicate extra study time to hands-on practice with these security features in your GitHub Enterprise environment.
How long should I spend preparing for GH-100?
With intermediate GitHub administration experience already in place, most candidates need 4 to 8 weeks of focused study. The exam tests practical skills, so labs and real-world scenarios matter more than memorizing facts. Budget time for hands-on configuration of security policies, Actions workflows, and identity management.
What happens on exam day when I take GH-100?
The exam is 100 minutes long and delivered online with proctoring. You will answer multiple choice and multiple select questions covering all five domains. You need a quiet private space, a stable internet connection, and a valid ID to proceed.
Can I retake GH-100 if I fail it?
Yes, you can retake the exam, but there is typically a waiting period between attempts. Check Microsoft's retake policy on the certification page when you register. Each attempt requires a new exam fee.
How long does the GitHub Administration certification stay valid?
Microsoft typically certifications remain valid for three years from the date you pass the exam. Check the official certification page for specific renewal requirements after that period ends.
What job roles should take GH-100?
This exam suits GitHub administrators, DevOps engineers managing GitHub infrastructure, security engineers implementing GitHub Advanced Security, and IT professionals migrating organizations to GitHub Enterprise. It validates your ability to configure and secure GitHub at enterprise scale.
Is GH-100 a prerequisite for other GitHub certifications?
GH-100 is the foundational GitHub Administration exam. Other GitHub certifications may build on this knowledge, but there are no formal prerequisites. It stands alone as a certification.
How does GH-100 differ from general GitHub knowledge or developer certifications?
GH-100 focuses entirely on administration, governance, security policies, and enterprise management rather than development or using GitHub features as a developer. It tests your ability to configure organization roles, manage permissions, audit activity, and enforce compliance across teams.
What are the key differences between managing GHEC, GHES, and personal accounts in the context of GH-100?
The exam expects you to understand deployment scenarios including GitHub Enterprise Cloud with Enterprise Managed Users, GHES (Server), and configurations with or without data residency. Each model has different identity management, licensing, and administrative capabilities that affect how you configure policies and access controls.