GitHub Certification Exam Prep

Study guides, practice exams, and flashcards for all GitHub certifications. 3 certifications available.

About GitHub Certifications

GitHub's certification track has three rungs. GH-900 GitHub Foundations is the entry point: it validates that you understand Git and GitHub from first principles — version control concepts, repositories, commits and branches, the GitHub Flow, and the collaboration surfaces (issues, pull requests, discussions) that day-to-day work runs on. It is deliberately not a developer-only exam: project managers, technical writers, and administrators who work inside GitHub are part of the target audience, and the questions test recognition and understanding rather than hands-on configuration. Expect roughly 75 questions over 120 minutes, with a scaled passing score of 700 out of 1000.

The Foundations blueprint (refreshed January 2026) spans seven domains. Git and GitHub basics carries the heaviest weight at 25–30%, followed by working with repositories, collaborating on GitHub, modern development practices (GitHub Actions, the Copilot plan tiers, Codespaces and github.dev), project management with Projects, privacy, security and administration, and the GitHub community — open source, Sponsors, InnerSource, and the Marketplace.

GH-200 GitHub Actions is the platform's automation credential and the most technical of the three. It assumes you already work inside GitHub and asks whether you can build the delivery pipeline: authoring workflows and reasoning about triggers, matrices, contexts and service containers; choosing correctly between starter workflows, reusable workflows and composite actions; writing and publishing custom actions; and running all of it at organization scale across runner groups, secrets and use policies. The January 2026 revision reorganized the blueprint into five domains and added material older prep books miss entirely — YAML anchors and merge keys, immutable actions, OIDC federation, and artifact attestations. Expect 100 minutes and a scaled passing score of 700 out of 1000, with interactive question types alongside multiple choice.

GH-300, the Copilot certification, sits above Foundations and covers considerably more than knowing how to accept a suggestion. It validates that you can work with Copilot across its surfaces (the IDE, the CLI, github.com and mobile) and that you understand what happens to your code along the way: how prompts are assembled, what the proxy filters, and where the model's limits sit. The exam runs 100 minutes with roughly 60 questions and a 70% passing score — and it is not solely a developer credential either, since organization-wide policy management, content exclusions, audit log events and subscription management through the REST API are all in scope.

Career value: Foundations signals platform fluency for any role that touches GitHub and is the natural first step; Actions is the one that maps to a job title, since owning CI/CD on GitHub is a DevOps and platform-engineering responsibility; and the Copilot credential signals both effective AI-assisted development and an understanding of the governance that has to sit around it. Taking them in that order — GH-900, then GH-200, then GH-300 — mirrors how organizations actually adopt the platform: collaboration first, automation second, AI enablement third.

All GitHub Certifications

Beginner

GitHub Foundations logo

[GH-900] GitHub Foundations

For beginners and professionals proving foundational Git and GitHub collaboration skills.

Intermediate

GitHub Actions logo

[GH-200] GitHub Actions

For DevOps engineers and developers proving they can automate and secure CI/CD with GitHub Actions.

GitHub Copilot logo

[GH-300] GitHub Copilot

For developers proving proficiency with GitHub Copilot in AI-assisted software development.

Recommended Learning Paths

GitHub Certification Journey

Key Topic Areas

The core domains tested across GitHub certifications. Each badge links to the study guide for an exam that covers the area.

Git and GitHub Basics

Core Git concepts: repositories, commits, branches · Accounts, organizations, and Enterprise · The GitHub Flow · Markdown for clear communication · GitHub Desktop and GitHub Mobile

Covered in:GH-900

Working with Repositories

Repository structure and key files · Creating and organizing repositories · Managing files within a repository · Repository insights and metrics · Maintenance best practices

Covered in:GH-900

Collaboration on GitHub

Issues, pull requests, and discussions · Linking PRs to issues and templates · Notifications and workflow management · Gists, wikis, and GitHub Pages

Covered in:GH-900

Modern Development Practices

GitHub Actions for automation · Copilot for Individuals, Business, and Enterprise · Codespaces and dev containers · github.dev vs. Codespaces

Covered in:GH-900

Project Management

GitHub Projects and layouts · Labels, milestones, and workflow rules · Saved replies and assignees · Project insights for tracking progress

Covered in:GH-900

Privacy, Security and Administration

Securing accounts: 2FA and passkeys · Access permissions and roles · Enterprise Managed Users · Repository visibility and branch protection · Organization settings, teams, and roles

Covered in:GH-900

The GitHub Community

Open source and GitHub Sponsors · Following users and organizations · The GitHub Marketplace · InnerSource principles · Forks, templates, and discoverability

Covered in:GH-900

Author and Manage Workflows

Workflow triggers: scheduled, manual, webhook and repository events · workflow_dispatch inputs and workflow_call mapping · Jobs, steps, conditional logic and job dependencies · Strategy matrices with include/exclude, fail-fast and max-parallel · YAML anchors, aliases and merge keys · Service containers, contexts and expression evaluation · Caching, artifacts, job summaries and environment protections

Covered in:GH-200

Consume and Troubleshoot Workflows

Diagnosing failed runs from logs and run history · Reading expanded anchors and matrix job names · Locating and downloading artifacts and logs · Starter workflows vs. reusable workflows vs. composite actions · Consuming organization-level and non-public templates

Covered in:GH-200

Author and Maintain Actions

JavaScript, Docker and composite action types · action.yml metadata, required files and directory structure · Workflow commands inside actions · Immutable actions and version pinning · Distribution models and Marketplace publishing · Versioning and release strategies

Covered in:GH-200

Manage GitHub Actions for the Enterprise

Distributing reusable components and templates · Controlling access to actions and organizational use policies · GitHub-hosted and self-hosted runners at scale · Runner groups, IP allow lists and networking · Preinstalled software and runtime installation · Encrypted secrets and variables across org, repo and environment scopes

Covered in:GH-200

Secure and Optimize Automation

Environment protections and approval gates · Script injection mitigation and least privilege · GITHUB_TOKEN lifecycle vs. PATs and granular permissions · OIDC federation to cloud providers · Pinning third-party actions to commit SHAs · Artifact attestations and build provenance · Cache and retention tuning for cost

Covered in:GH-200

Copilot Features and Surfaces

Code completion in the IDE · Copilot Chat and inline chat · GitHub Copilot CLI · Agent, edit and plan modes · Copilot on github.com and mobile · Code review and PR summaries

Covered in:GH-300

Responsible AI Use

Risks and limitations of generative AI · Ethical and responsible usage · Potential harms and mitigations · Why AI output must be validated

Covered in:GH-300

Data Handling and Architecture

Data usage flow and sharing · Input processing and prompt building · Proxy filtering and post-processing · The code suggestion lifecycle · Limitations of LLMs

Covered in:GH-300

Prompt Engineering and Context

Prompt structure and context · How Copilot determines context · Zero-shot and few-shot prompting · Chat history and prompt reuse · Instructions and prompt files

Covered in:GH-300

Developer Productivity

Code generation and refactoring · Documentation generation · Unit and integration tests · Edge cases and assertions · Modernizing legacy code · Generating sample data

Covered in:GH-300

Privacy, Policies and Safeguards

Content exclusions · Duplication detection · Organization-wide policy management · Audit log events · Managing subscriptions with the REST API · Ownership of outputs

Covered in:GH-300

Frequently Asked Questions

Explore More Certifications

Browse all certification paths across AWS, Azure, CompTIA, and more.

Browse All Certifications