When does secret scanning skip reporting a secret?
A.
When the secret is in a set of credentials from a service provider.
B.
When the secret is part of a new commit.
C.
After switching a private repository to a public repository.
D.
When the secret has been revoked from the repository.
The Answer Is:
A
This question includes an explanation.
Explanation:
This question is referring to user-facing repository alerts for partner secrets. When GitHub detects authentication credentials belonging to a participating service provider in public content, GitHub can send a partner alert directly to that provider. Partner alerts are not displayed as normal repository secret-scanning alerts to repository administrators. The provider can then validate, revoke, or otherwise remediate the exposed credential. By contrast, newly committed secrets are precisely what secret scanning is designed to detect, changing repository visibility does not suppress scanning, and a revoked credential can still be detected even though validity information may indicate that it is inactive. Thus, interpreted in the context of repository-user reporting, A is the correct answer: supported partner credentials can be reported directly to the issuing provider rather than surfaced as a normal user alert.
GH-500 PDF/Engine
Printable Format
Value of Money
100% Pass Assurance
Verified Answers
Researched by Industry Experts
Based on Real Exams Scenarios
100% Real Questions
Get 70% Discount on All Products,
Use Coupon: "coponace"