certslothcertsloth
GH-900/Topic 06

GitHub / Foundational

Account Security, Teams and Repository Governance

2 min read5 recall promptsReviewed 2026-10-10

Memory hook: Authenticate the person; authorize the action; protect the shared branch.

Must remember

Protect accounts with supported two-factor methods or passkeys and maintain safe recovery options. A passkey uses public-key authentication and can provide phishing-resistant sign-in. Credentials used by tools need their own scope, expiration and revocation strategy; do not share a human account to simplify automation.

Repository roles grant different capabilities. Organization teams simplify group access and reviewer coordination. Owners administer broad settings; routine work should use narrower roles. Internal repositories are intended for eligible enterprise audiences, while private repositories use explicitly controlled access.

Branch protection and rulesets can require pull requests, reviews, status checks and other conditions. Evaluate bypass actors and administrative exemptions. A rule that allows every administrator to bypass controls has a different risk profile from one with tightly controlled exceptions. Required checks must use trustworthy workflows.

Enterprise Managed Users are provisioned and governed through an organization's identity provider under the enterprise model. They differ from inviting ordinary personal accounts into an organization, including collaboration constraints. Organization/enterprise Copilot policies govern eligible features and usage; a personal preference cannot necessarily override them.

Dependency alerts, code scanning and secret scanning address different risks: vulnerable dependencies, supported code patterns and exposed credentials. Availability depends on product/plan/repository settings. A secret finding requires revocation/rotation and investigation; deleting the line is insufficient. Audit logs help investigate administrative changes but do not replace appropriate prevention.

Choose under exam pressure

Requirement Choice and reason
Manage access for a team of engineers Organization team with scoped repository roles.
Require review before default-branch changes Protection/ruleset with controlled bypass.
Central identity lifecycle for enterprise users Evaluate Enterprise Managed Users and its constraints.

Traps

  • 2FA does not make every automation token safe.
  • A required check is weak if untrusted code can forge or bypass its result.

Active recall

1. Authentication versus authorization?

Prove identity versus decide allowed actions.

2. Why use teams?

To manage group access and collaboration consistently.

3. Why inspect bypass settings?

They determine who can circumvent normal branch requirements.

4. What should happen to an exposed token?

Revoke/rotate it, investigate use and remove exposure through the proper process.

5. EMU versus a normal invited account?

Enterprise-provisioned managed identity versus a personally controlled account granted organization access.

Sources

CLOSE THE NOTES. EXPLAIN THE CHOICE.

How well could you recall it?

Your next review is based on this answer. Progress stays in this browser.

Search across every published topic.