Enabling CodeQL Scanning for C# Repositories with a GitHub Actions CodeQL Workflow

Automate security and compliance scanning
Answer Correct answer: D — CodeQL scanning runs as a GitHub Actions workflow invoking the CodeQL action, so each repository needs the workflow; Dependabot handles dependencies.

You use GitHub Enterprise for source control repositories. The repositories store C# code. You need to enable CodeQL scanning for the repositories. What should you do?

  1. Enable Dependabot security updates.
  2. Enable Dependabot alerts.
  3. Configure a required GitHub Actions workflow for all the repositories.
  4. Push a GitHub Actions workflow to all the repositories. Correct Answer

Community Votes

D
100%

100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

CodeQL scanning runs as a GitHub Actions workflow using the CodeQL action, so the analysis is enabled by placing a CodeQL workflow in each repository. Code scanning is therefore configured through committed workflow code rather than through a dependency management feature.

GitHub Enterprise repositories hold C# code and CodeQL scanning must be enabled for them. CodeQL analysis is executed by a workflow, so the repositories need a workflow that runs the CodeQL action, and the question is which approach achieves that across the repositories.

Enabling Dependabot alerts or Dependabot security updates, which manage vulnerable dependency versions rather than performing static analysis of the code. Configuring a required workflow constrains which workflows may run but does not by itself create the CodeQL analysis workflow.

Community Discussion (3 comments)

swk1az400 👍 1 Selected: D
COPILOT: Yes, I'm sure. To enable CodeQL scanning for your GitHub Enterprise repositories, you should: D. Push a GitHub Actions workflow to all the repositories. Here’s a bit more detail on why this is the correct approach: CodeQL scanning is implemented through GitHub Actions workflows. By pushing a workflow file to each repository, you ensure that CodeQL analysis is configured and runs automatically on your codebase. This workflow will include steps to initialize CodeQL, analyze your code, and upload the results to GitHub for review.
fuchsm999 👍 2 Selected: D
D. Push a GitHub Actions workflow to all the repositories. Explanation: To enable CodeQL scanning, you need to create and configure a GitHub Actions workflow that performs the CodeQL analysis. This workflow must be added to each repository you want to scan. Dependabot security updates and alerts (options A and B) are related to dependency management, not CodeQL. While configuring a required workflow (option C) can enforce scanning, you must first deploy the workflow to the repositories (option D).
MrAZ105 👍 1
Copilot Sent by Copilot: To enable CodeQL scanning for your repositories in GitHub Enterprise, you should: D. Push a GitHub Actions workflow to all the repositories. This involves adding a CodeQL workflow file to each repository, which uses the github/codeql-action to run CodeQL analysis.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

CodeQL scanning is implemented through GitHub Actions: the analysis runs from a workflow that invokes the CodeQL action against the repository's languages. For C# code, that means each repository needs a CodeQL workflow present so the analysis actually executes, which is what pushing a GitHub Actions workflow to the repositories accomplishes. Because CodeQL performs semantic code analysis rather than dependency version management, the enabling action is the workflow and not a Dependabot setting. The vote was unanimous at 100 for D. fuchsm999 gave the most complete explanation, noting that the CodeQL analysis workflow must be added to each repository to be scanned, and that Dependabot options are about dependency management rather than CodeQL.

Why the Other Options Are Wrong

Enabling Dependabot alerts (B) surfaces known vulnerable dependencies from the GitHub Advisory Database, which is a different mechanism from CodeQL's static analysis of the code itself, so a repository with Dependabot alerts can still have unanalyzed code defects. Enabling Dependabot security updates (A) goes one step further by automatically raising pull requests that bump vulnerable dependencies, which again addresses version management rather than running CodeQL. Configuring a required GitHub Actions workflow for all the repositories (C) is the closest distractor, and fuchsm999 addressed it directly: a required workflow rule controls which workflows are permitted to run in the repository, but it does not supply the CodeQL analysis workflow itself, so the analysis still would not execute.

Community Comment Notes

The community was unanimous at 100 for D. fuchsm999 supplied the substantive reasoning, distinguishing CodeQL analysis workflows from the Dependabot dependency features and explicitly noting why the required-workflow option does not substitute. swk1az400 and MrAZ105 both posted AI-generated confirmations that pushing a CodeQL workflow file to each repository using the github/codeql-action is what enables the scanning, which is correct on the mechanism even though the reasoning is machine-generated. The practical detail worth noting is that the workflow must exist in each repository, since the configuration is per-repository rather than account-wide.

Official Reference

Related Analysis

Practice All AZ-400 Questions

Access 100 questions with complete answers and detailed explanations.

View Full AZ-400 Practice Test →

← Back to AZ-400 Study Guide