Enabling CodeQL Scanning for C# Repositories with a GitHub Actions CodeQL Workflow
You use GitHub Enterprise for source control repositories. The repositories store C# code. You need to enable CodeQL scanning for the repositories. What should you do?
Community Votes
100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
CodeQL scanning runs as a GitHub Actions workflow using the CodeQL action, so the analysis is enabled by placing a CodeQL workflow in each repository. Code scanning is therefore configured through committed workflow code rather than through a dependency management feature.
GitHub Enterprise repositories hold C# code and CodeQL scanning must be enabled for them. CodeQL analysis is executed by a workflow, so the repositories need a workflow that runs the CodeQL action, and the question is which approach achieves that across the repositories.
Enabling Dependabot alerts or Dependabot security updates, which manage vulnerable dependency versions rather than performing static analysis of the code. Configuring a required workflow constrains which workflows may run but does not by itself create the CodeQL analysis workflow.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
CodeQL scanning is implemented through GitHub Actions: the analysis runs from a workflow that invokes the CodeQL action against the repository's languages. For C# code, that means each repository needs a CodeQL workflow present so the analysis actually executes, which is what pushing a GitHub Actions workflow to the repositories accomplishes. Because CodeQL performs semantic code analysis rather than dependency version management, the enabling action is the workflow and not a Dependabot setting. The vote was unanimous at 100 for D. fuchsm999 gave the most complete explanation, noting that the CodeQL analysis workflow must be added to each repository to be scanned, and that Dependabot options are about dependency management rather than CodeQL.Why the Other Options Are Wrong
Enabling Dependabot alerts (B) surfaces known vulnerable dependencies from the GitHub Advisory Database, which is a different mechanism from CodeQL's static analysis of the code itself, so a repository with Dependabot alerts can still have unanalyzed code defects. Enabling Dependabot security updates (A) goes one step further by automatically raising pull requests that bump vulnerable dependencies, which again addresses version management rather than running CodeQL. Configuring a required GitHub Actions workflow for all the repositories (C) is the closest distractor, and fuchsm999 addressed it directly: a required workflow rule controls which workflows are permitted to run in the repository, but it does not supply the CodeQL analysis workflow itself, so the analysis still would not execute.Community Comment Notes
The community was unanimous at 100 for D. fuchsm999 supplied the substantive reasoning, distinguishing CodeQL analysis workflows from the Dependabot dependency features and explicitly noting why the required-workflow option does not substitute. swk1az400 and MrAZ105 both posted AI-generated confirmations that pushing a CodeQL workflow file to each repository using the github/codeql-action is what enables the scanning, which is correct on the mechanism even though the reasoning is machine-generated. The practical detail worth noting is that the workflow must exist in each repository, since the configuration is per-repository rather than account-wide.Official Reference
Related Analysis
Practice All AZ-400 Questions
Access 100 questions with complete answers and detailed explanations.
View Full AZ-400 Practice Test →