Microsoft DevOps Engineer Expert AZ-400 Practice Question
You are integrating GitHub Advanced Security with Microsoft Defender for Cloud. The DevOps security connector for GitHub has been created and the Azure Security for GitHub app is installed with access to all repositories. In the organization-level Code security and analysis settings, only Dependabot alerts and Code scanning are currently enabled. Defender for Cloud is receiving vulnerability and code-quality findings but no secrets-related findings. What should you do to ensure secret-scanning alerts appear in Defender for Cloud?
Grant the Azure Security for GitHub app the Administration permission on each repository.
Enable Secret scanning - Push protection for the organization's private repositories.
Turn on Dependabot security updates for every repository.
Create branch protection rules that require successful code-scanning checks before merge.
To receive secret-related findings, GitHub Advanced Security's 'Secret scanning' feature must be enabled for the repositories. Defender for Cloud's DevOps security connector ingests the alerts generated by this feature. The scenario states that only Dependabot and Code scanning are enabled, so Secret scanning is currently off. Enabling 'Secret scanning' will scan the repository's history for exposed secrets, and enabling the 'Push protection' sub-feature will also block and alert on new secrets being committed. Both types of alerts are then surfaced in Defender for Cloud. The other options are incorrect because they do not generate secret scanning alerts: granting administrative permissions is unnecessary for reading security events, Dependabot handles dependency vulnerabilities, and branch protection rules enforce code scanning checks.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is GitHub's Secret scanning?
Open an interactive chat with Bash
What is the role of Microsoft Defender for Cloud in integrating with GitHub Advanced Security?
Open an interactive chat with Bash
What is Push protection in GitHub Advanced Security's Secret scanning, and why is it important?
Open an interactive chat with Bash
Microsoft DevOps Engineer Expert AZ-400
Develop a security and compliance plan
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .