Purging a Sensitive Data.txt from Git History with bfg and git filter-repo
You manage source control by using GitHub. You have a file named Data.txt that contains sensitive data. A user pushes Data.txt to a repository. You need to purge the file from the repository. Which two commands can you use? Each correct answer presents a complete solution. NOTE: Each correct solution is worth one point.
Community Votes
75% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Both bfg and git filter-repo rewrite the entire history to remove the file from every commit, and because the blob is gone from the rewritten history rather than merely unlinked, a fresh clone can never recover it. git rm alone would leave the object reachable in history.
A user pushed a file named Data.txt containing sensitive data to a repository, and the file must be purged. Deleting the current version is insufficient because the blob remains in the repository history and stays reachable, so the history itself has to be rewritten with a purpose-built tool.
Using git rm to delete the file. That removes it from the working tree and the current commit, but the blob stays in earlier commits and remains retrievable, so it does not purge the sensitive data from the repository.
Community Discussion (8 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The requirement is to purge Data.txt, which contains sensitive data, meaning the data must be removed from the repository rather than just deleted from the current checkout. Two commands do this by rewriting history: bfg with the delete-files option erases the file across all commits, and git filter-repo with the invert-paths option removes the path from the recorded history. Because both rewrite every commit, the blob is eliminated rather than merely unreferenced, and any new clone contains no trace of it. The vote was 75 for C and 25 for E, so the community was confident both selections are required. a58817 linked a detailed how-to guide for deleting sensitive data from Git covering the C and E combination, and fuchsm999 and Mattt both stressed that two options must be chosen because the question asks for two commands.Why the Other Options Are Wrong
git checkout (A) and git checkout (B) are printed identically in this question, which is a defect in how the options were exported, and in any case checkout only switches branches or restores files in the working tree; it does not touch recorded history and therefore cannot remove anything from the repository's past. git rm data.txt (D) is the most commonly chosen wrong answer, and it fails precisely because it is a working tree and staging operation. The blob is still stored in earlier commits, so a user who checks out an earlier commit or clones the repository can still recover the sensitive content, which means the data is not actually purged.Community Comment Notes
The community was confident at 75 votes for C and 25 for E, with the split reflecting that C and E are the two halves of one correct answer rather than genuine disagreement. a58817 supplied the authoritative reference with a link to a guide on removing sensitive data from Git that covers exactly the C and E pairing. Dankho added a useful nuance, observing that the question is asking for two commands where each option is a single command, and that a simple delete without a complex history rewrite points to BFG, which helps explain why C carries the larger share of votes.Related Analysis
Practice All AZ-400 Questions
Access 100 questions with complete answers and detailed explanations.
View Full AZ-400 Practice Test →