exam questions

Exam AZ-400 All Questions

View all questions & answers for the AZ-400 exam

Exam AZ-400 topic 5 question 41 discussion

Actual exam question from Microsoft's AZ-400
Question #: 41
Topic #: 5
[All AZ-400 Questions]

You have a public GitHub repository named Public1.

A commit is made to Public1. The commit contains a pattern that matches a regular expression.

Who is notified first when the commit is made?

  • A. the administrator of the GitHub organization
  • B. the committer
  • C. the owner of Public1
  • D. the secret scanning partner
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
zellck
Highly Voted 1 year, 4 months ago
Selected Answer: D
D is the answer. https://docs.github.com/en/code-security/secret-scanning/about-secret-scanning#about-secret-scanning-alerts-for-partners When you make a repository public, or push changes to a public repository, GitHub always scans the code for secrets that match partner patterns. Public packages on the npm registry are also scanned. If secret scanning detects a potential secret, we notify the service provider who issued the secret. The service provider validates the string and then decides whether they should revoke the secret, issue a new secret, or contact you directly. Their action will depend on the associated risks to you or them. You cannot change the configuration of secret scanning for partner patterns on public repositories.
upvoted 15 times
KumaTed
1 year, 4 months ago
yes, should be D
upvoted 1 times
...
kay000001
1 year, 4 months ago
Amongst my other research, I agree with you and the link you've provided.
upvoted 2 times
...
...
ozbonny
Most Recent 8 months, 1 week ago
Selected Answer: D
Detection and notification: When a commit containing a matching pattern is made, GitHub notifies the relevant service provider directly. This happens even before any other party is informed. Other stakeholders: While the committer, owner, and organization administrator might receive notifications about the commit, they won't be notified first about the specific secret detection.
upvoted 1 times
...
vsvaid
10 months, 2 weeks ago
Selected Answer: D
Secret scanning partner
upvoted 1 times
...
renzoku
1 year, 3 months ago
Selected Answer: D
D. the secret scanning partner Scan for potential secrets. When the commit is made, the secret scanning partner is the first to be notified. Then takes appropriate actions, such as alerting the owner or taking security measures.
upvoted 2 times
...
xRiot007
1 year, 3 months ago
A pattern matching a regular expression might be a token, a password, a secret of some kind or some other sensitive data that could be a potential security issue. The answer is D - a secret scanning partner. This is basically a bot that scans your changes, detects the aforementioned issues and can notify you to take corrective actions.
upvoted 1 times
...
Rugaroo
1 year, 4 months ago
Selected Answer: D
ChatGPT answer: Based on the information provided, the correct answer would be D. the secret scanning partner. When a commit is made to a public GitHub repository and it contains a pattern that matches a regular expression, GitHub's secret scanning feature is triggered. The secret scanning partner associated with GitHub is notified first to perform an analysis and identify any potential secrets or sensitive information in the commit.
upvoted 3 times
...
KumaTed
1 year, 4 months ago
Selected Answer: A
the provided answer is right. the link provided by Pamban and zellck is right, but please notice the next part. https://docs.github.com/en/code-security/secret-scanning/about-secret-scanning#about-secret-scanning-alerts-for-partners Secret scanning alerts for users are available for free on all public repositories. When you enable secret scanning for a repository, GitHub scans the code for patterns that match secrets used by many service providers. When the scan is completed, GitHub sends an email alert to the enterprise and organization owners, even if no secrets were found.
upvoted 1 times
...
Pamban
1 year, 4 months ago
Selected Answer: D
https://docs.github.com/en/code-security/secret-scanning/about-secret-scanning#about-secret-scanning-alerts-for-partners
upvoted 2 times
...
[Removed]
1 year, 4 months ago
Selected Answer: C
I believe its C. I can't seem to find no reference online about notification chain order. But it makes sense from my experience that the owners\maintainers of the repository are the first one being notified.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago