Courseiva

SC-100 GitHub secret scanning Practice Question

You are a security architect for a software development company. The company uses GitHub for source control and Azure DevOps for CI/CD. They have a large number of repositories and want to ensure that secrets (e.g., API keys, connection strings) are never committed to code. They also want to scan pull requests for secrets before merging. The company has Microsoft Defender for Cloud and Microsoft Purview available. You need to design a solution that prevents secret leaks. What should you use?

⚠ Common exam trap

Candidates may think Microsoft Defender for Cloud can scan GitHub repositories for secrets, but that is not a feature of Defender for Cloud. GitHub secret scanning is separate.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable GitHub secret scanning for all repositories. Configure push protection to block commits containing secrets. Use custom patterns to scan for company-specific secrets.

GitHub secret scanning can scan repositories for known secret patterns and supports custom patterns for company-specific secrets. Push protection blocks commits containing secrets before they are pushed. Option A is incorrect because Microsoft Defender for Cloud does not provide built-in secret scanning for GitHub repositories; GitHub secret scanning is a separate feature. Option B is incorrect because Azure Key Vault stores secrets but does not scan code for secrets. Option C is incorrect because Microsoft Purview Information Protection is for data classification and labeling, not for secret scanning in source code.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable Microsoft Defender for Cloud's 'Secrets scanning' feature for GitHub repositories.

    Why it's wrong here

    Defender for Cloud's secrets scanning surfaces exposed credentials in GitHub repositories, but it detects after commit rather than blocking pull requests before merge. It is tempting because it covers GitHub at scale. The requirement to scan pull requests pre-merge needs GitHub Advanced Security secret scanning with push protection.

  • ✗

    Use Azure Key Vault to store secrets and enforce policies that require developers to use Key Vault references.

    Why it's wrong here

    Key Vault stores secrets centrally and Key Vault references keep them out of configuration, but nothing prevents a developer committing a literal secret to a repository, and no pull request scanning occurs. It is tempting because vaulting is a genuine secrets-management control. Detecting and blocking committed secrets requires repository secret scanning.

  • ✗

    Use Microsoft Purview Information Protection to scan repositories and classify secrets.

    Why it's wrong here

    Purview Information Protection applies sensitivity labels and classification to data at rest and in transit, not to source code repositories, and it cannot scan pull requests. It is tempting because Purview classifies sensitive information. Preventing secret leaks in GitHub requires GitHub Advanced Security secret scanning with push protection.

  • ✓

    Enable GitHub secret scanning for all repositories. Configure push protection to block commits containing secrets. Use custom patterns to scan for company-specific secrets.

    Why this is correct

    GitHub secret scanning with push protection blocks commits containing detected secrets before they reach the repository, while custom patterns extend detection to company-specific formats. This satisfies the stem's requirements to prevent secret leaks and scan pull requests before merging.

About these practice questions

Courseiva writes every SC-100 question from scratch — 605 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.