AZ-400 Practice Question: Design and implement build and release pipelines
Your organization uses GitHub Actions for CI/CD. You need to ensure that secrets stored in GitHub are not exposed in logs. A developer reports that a secret value appeared in the workflow run log. What is the most likely reason?
⚠ Common exam trap
AZ-400 often tests the misconception that GitHub Actions masks secrets in all cases, when in fact masking can be bypassed by transforming the secret value before printing.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The secret was printed using a script that bypassed automatic masking.
GitHub Actions automatically masks secrets in logs by replacing their values with '***', but this masking can be bypassed if a script transforms the secret (e.g., base64 encoding, splitting, or printing it in a way that changes its exact string) before outputting it. The most likely reason a secret value appeared in the log is that the script printed it in a form that bypassed the automatic masking. This is a known limitation of GitHub's secret masking.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The workflow was triggered via repository_dispatch.
Why it's wrong here
The event type that triggers a GitHub Actions workflow, such as repository_dispatch, workflow_dispatch, or push, has no effect on the runner's secret-masking behavior. Secret values are masked based on GitHub's automatic detection of the value in logs, regardless of the triggering event.
- ✓
The secret was printed using a script that bypassed automatic masking.
Why this is correct
Correct: When a script or action writes a secret value to stdout in a format that GitHub's log redaction does not recognize—for example, by printing it in base64, with escaped characters, or through an intermediate environment variable that is not pre-registered as a secret—the automatic masking may fail and expose the value. GitHub masks secrets that appear verbatim in the log, but only if the exact string is seen; any transformation bypasses that protection.
- ✗
The secret name was used in the log output.
Why it's wrong here
Secret names are never masked by GitHub Actions; only their corresponding values are. Displaying the name of a secret, such as 'MY_SECRET', in a log will not trigger redaction, so this could not be the cause of a secret value appearing unmasked.
- ✗
The workflow used 'debug' log level.
Why it's wrong here
The log-level setting (e.g., 'debug') controls how much diagnostic output is produced, not whether secret masking is applied. GitHub Actions automatically masks secrets in all log levels, unless the secret value is modified or bypassed by the workflow code itself.
Go deeper
Related to this question
About these practice questions
One of 696 original AZ-400 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This AZ-400 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-400 exam.