Your organization uses GitHub Actions for CI/CD. You need to ensure that secrets are securely passed to workflows without being exposed in logs. What should you use?
GitHub Secrets are repository-level encrypted values that are never stored in the workflow file; GitHub encrypts each secret with a public key using the libsodium sealed box algorithm before storing it and exposes it to workflow runs only as the secrets context. During a run, GitHub injects the secret into the runner environment and automatically redacts its value from logs, and secrets are not available to pull requests from forks unless explicitly configured. This provides a secure, native mechanism for storing sensitive data like API tokens with per-environment scoping and rotation through the GitHub UI or API.
Why this answer
GitHub Secrets (Option A) is the correct choice because GitHub Actions provides a built-in secrets management system that encrypts sensitive values at rest and masks them in all workflow logs. When you reference a secret using ${{ secrets.MY_SECRET }}, GitHub automatically redacts the value from any log output, ensuring it is never exposed during execution.
Exam trap
The trap here is that candidates confuse Azure DevOps encrypted variables with GitHub Secrets, assuming Azure Key Vault integration works identically in GitHub Actions, when in fact GitHub Actions requires a separate action or manual API calls to fetch secrets from Azure Key Vault.
How to eliminate wrong answers
Option B is wrong because environment variables defined directly in the workflow YAML file are stored in plain text and can be printed or leaked in logs, offering no security for sensitive data. Option C is wrong because hardcoding secrets in the workflow file commits them to the repository history, making them visible to anyone with repository access and violating security best practices. Option D is wrong because Azure Key Vault with Azure DevOps encrypted variables is a valid approach for Azure Pipelines, but the question specifically asks about GitHub Actions, where Azure Key Vault integration is not natively supported without additional custom steps or third-party actions.