As a developer, you need to use GitHub Actions to deploy a microservice that requires runtime access to a secure token. This token is used by a variety of other microservices managed by different teams in different repos. To minimize management overhead and ensure the token is secure, which mechanisms should you use to store and access the token? (Choose two.)
Correct Answer: C,E
Using a corporate secret store like HashiCorp Vault provides a secure, centralized location for sensitive information. GitHub Actions can then retrieve and store the token securely during deployment by setting it as an environment variable, ensuring the token remains secure and accessible at runtime. Storing the token as an organizational-level encrypted secret in GitHub ensures it is accessible across multiple repositories, minimizing management overhead. GitHub Actions can then use this secret during deployment by setting it as an environment variable, allowing the microservice to access it securely at runtime.
GH-200 Exam Question 32
What are the two types of environment protection rules you can configure? (Choose two.)
Correct Answer: A,C
Required reviewers is a protection rule where you can specify that certain individuals or teams must review and approve the workflow run before it can proceed. This is used to enforce approvals before certain steps or environments are accessed. Wait timer is a protection rule that introduces a delay before a workflow can proceed to the next stage. This is useful for adding time-based constraints to the deployment process or ensuring that certain conditions are met before a workflow continues.
GH-200 Exam Question 33
You are a DevOps engineer working on a custom action. You want to conditionally run a script at the start of the action, before the main entrypoint. Which code block should be used to define the metadata file for your custom action?
Correct Answer: B
For JavaScript custom actions, the metadata file supports lifecycle scripts through the runs section. The correct key for a script that runs before the main action entrypoint is pre, and the correct conditional key for controlling whether that pre-script runs is pre-if. Therefore, option B is the only valid metadata structure. GitHub Actions does not use start, start-if, before, or before-if as action metadata keys. Option C is also invalid because pre-if only defines a condition; it cannot contain both a condition and a script reference in one line. In GitHub Actions exam terms, this tests custom action metadata, JavaScript action lifecycle hooks, and conditional execution before the main action logic.
GH-200 Exam Question 34
As a developer, you are using a Docker container action in your workflow. What is required for the action to run successfully?
Correct Answer: A
GH-200 Exam Question 35
As a developer, you need to create a custom action written in Python. Which action type should you choose?
Correct Answer: C
GitHub officially defines three major custom-action types: JavaScript actions, Docker container actions, and composite actions. There is no separate native Python action type. A Docker container action is appropriate when the implementation is written in Python because the container can package the Python runtime, application code, dependencies, and required operating-system components together. GitHub states that Docker container actions can use any base Docker image and therefore any programming language. This provides a predictable execution environment independent of the software preinstalled on the runner. JavaScript actions specifically execute packaged JavaScript using a supported Node.js runtime. Composite actions primarily combine multiple workflow steps and commands. For a self-contained custom action implemented in Python with its runtime and dependencies packaged alongside it, the Docker container action is the correct choice.