Git & GitHub Interview Mock sample questions with answers

10 questions from the Git & GitHub Interview Mock practice bank, spread across its domains. Pick your answer, then open the explanation to see why each option is right or wrong.

  1. Question 1Branching, Rewriting and Undoing

    Your local main and origin/main have diverged, and pull.rebase and pull.ff aren't set. Plain git pull fails. Which two commands complete the pull? (Choose two.)

    Choose 2.

    • A

      git pull --rebase

    • B

      git pull --no-rebase

    • C

      git pull --ff-only

    • D

      git pull --squash

    • E

      git pull --force

    Show the answer and explanation

    Answer: A and B

    Since Git 2.33, a pull with divergent branches and no configured strategy stops with "fatal: Need to specify how to reconcile divergent branches." Choose explicitly: --rebase (or pull.rebase true) for linear history, --no-rebase (or pull.rebase false) to merge, or --ff-only, which only succeeds when no local commits exist. Verified with Git 2.55.

    Why the other options are wrong

    • C. The branches have diverged, so a fast-forward is impossible and it fails.

    • D. A squash merge stages changes without recording a merge; it doesn't reconcile the histories.

    • E. --force only affects ref updates during fetch; it doesn't choose a reconcile method.

  2. Question 2Advanced Git and GitHub

    A team compares reusable workflows with composite actions. Which two statements are true? (Choose two.)

    Choose 2.

    • A

      A reusable workflow is called with uses: at the job level

    • B

      A called workflow gets secrets only if passed or via secrets: inherit

    • C

      A composite action can choose its own runs-on runner

    • D

      A reusable workflow can be invoked from a step's run: script

    • E

      Composite actions can define several jobs with needs: links

    Show the answer and explanation

    Answer: A and B

    Reusable workflows (on: workflow_call) are used as an entire job via jobs.<id>.uses, can contain several jobs, and receive secrets explicitly or with secrets: inherit. Composite actions bundle steps and are used as a single step inside a job.

    Why the other options are wrong

    • C. Composite actions run as steps inside the caller's job.

    • D. It can only be referenced at job level with uses:.

    • E. Composite actions contain steps only, never jobs.

  3. Question 3Git Fundamentals

    In a repository, git config --show-origin --get user.name prints:

    file:.git/config	LocalName

    What does this tell you?

    • A

      The value comes from the repository's own config, which beats global

    • B

      Your global config has no user.name, so Git fell back to the local file

    • C

      The name will be used for all repositories on this machine

    • D

      Commits will be rejected until the global name matches

    Show the answer and explanation

    Answer: A

    --show-origin prints the file each value came from. .git/config is the local level, which overrides the global and system files for this repository. --show-scope prints the level name (local) instead. Verified with Git 2.55.

    Why the other options are wrong

    • B. Local wins regardless; the global file may well set a different name.

    • C. .git/config belongs to this repository only.

    • D. Git never compares levels; it simply uses the highest-priority value.

  4. Question 4Collaboration

    Branch protection on main requires 1 approval and has "Dismiss stale pull request approvals when new commits are pushed" enabled. After Bob approves, the author pushes a one-line typo fix. What is the PR's state?

    • A

      Still approved, because the change is tiny

    • B

      Bob's approval is dismissed and a new approval is needed

    • C

      Still approved, but the PR becomes a draft until Bob re-reviews

    • D

      Blocked until an admin overrides branch protection

    Show the answer and explanation

    Answer: B

    GitHub records the diff a reviewer approved. If it changes (new commits, Update branch, or a related merge into the base), the approval is dismissed as stale and someone must approve again.

    Why the other options are wrong

    • A. GitHub doesn't judge size; any change to the diff makes the approval stale.

    • C. Stale approvals don't convert a PR to a draft.

    • D. Any eligible reviewer can approve again; no admin is required.

  5. Question 5Branching, Rewriting and Undoing

    Before running git reset --hard, your tree has: an edited tracked file a.txt, an untracked file scratch.txt, an ignored debug.log, and a new file feature.ts that you git add-ed but never committed. Which of these files exist afterwards?

    • A

      a.txt (committed content), scratch.txt and debug.log

    • B

      All four, with feature.ts back to untracked

    • C

      Only a.txt, since a hard reset cleans every other file

    • D

      a.txt, scratch.txt and feature.ts, but not debug.log

    Show the answer and explanation

    Answer: A

    Verified with Git 2.55: after reset --hard, the directory contained .gitignore, a.txt, scratch.txt (untracked) and the ignored log, while the staged-new file was gone. Its content survives only as a dangling blob (git fsck --lost-found).

    Why the other options are wrong

    • B. Hard reset deletes index-only files from disk rather than unstaging them.

    • C. Untracked and ignored files are left alone; only git clean deletes them.

    • D. reset never looks at ignored files, and the staged new file is the one removed.

  6. Question 6Advanced Git and GitHub

    In job build, step ver runs echo "version=1.4.0" >> "$GITHUB_OUTPUT". Job release has needs: build and reads ${{ needs.build.outputs.version }}, but it is empty. What is missing?

    • A

      ver must use the old ::set-output command for values used across jobs

    • B

      An outputs: map on build exposing steps.ver.outputs.version

    • C

      release must also run on the same runner that ran build

    • D

      Outputs only pass between jobs when stored as artifacts

    Show the answer and explanation

    Answer: B

    Step outputs are visible only inside their job. To expose one, declare jobs.build.outputs.version: ${{ steps.ver.outputs.version }}; dependent jobs then read needs.build.outputs.version.

    Why the other options are wrong

    • A. GITHUB_OUTPUT works for this; set-output is deprecated.

    • C. Outputs are passed by GitHub, so jobs don't share a runner.

    • D. Artifacts carry files; small values go through job outputs.

  7. Question 7Git Fundamentals

    What does git log -L :parsePrice:src/money.js show?

    • A

      Every commit that touched src/money.js, with full patches

    • B

      Each commit that changed parsePrice, with diffs limited to it

    • C

      The line numbers where parsePrice is called across the repository

    • D

      The author of each line of parsePrice at HEAD

    Show the answer and explanation

    Answer: B

    Line-range log traces a region through history. -L <start>,<end>:<file> follows explicit line numbers, and -L :<funcname>:<file> uses a function-name regex to find the region. Each listed commit shows a patch restricted to that range, which is often the fastest way to answer "how did this function change?".

    Why the other options are wrong

    • A. A plain path filter would do that; -L narrows to one function.

    • C. That is a search task for git grep.

    • D. That would be git blame -L, which annotates rather than lists history.

  8. Question 8Collaboration

    A developer clones a private GitHub repository over HTTPS and enters their GitHub account password when prompted. Authentication fails. Why?

    • A

      HTTPS remotes only work for public repositories; private ones always require SSH

    • B

      GitHub no longer accepts account passwords for Git; use a token or SSH

    • C

      The password must be URL-encoded and placed inside the remote URL

    • D

      Private repositories must be forked before they can be cloned

    Show the answer and explanation

    Answer: B

    GitHub requires token-based authentication for Git over HTTPS: a personal access token (fine-grained or classic) or a credential manager using OAuth. Alternatively use SSH keys. Credential helpers such as Git Credential Manager store the token so you aren't asked every time.

    Why the other options are wrong

    • A. HTTPS works for private repositories with a token.

    • C. Embedding credentials in URLs is insecure and still wouldn't accept a password.

    • D. Cloning a private repository you can access needs no fork.

  9. Question 9Branching, Rewriting and Undoing

    Your team "Squash and merge"s a PR on GitHub. You keep committing on the same branch and open a second PR. Why does the new PR also list the commits from the first one?

    • A

      main has one squashed commit, not your individual commits

    • B

      Squash merging resets the source branch to the PR's base commit

    • C

      The second PR was opened against the wrong base

    • D

      GitHub caches the commit list of a branch from its earlier PR

    Show the answer and explanation

    Answer: A

    A squash merge creates one new commit on main containing the combined change, so your original commits never become part of main's history. Further work on the same branch still sits on top of them. Start a new branch from the updated main, or git rebase --onto origin/main <last-old-commit> to move only the new commits.

    Why the other options are wrong

    • B. Nothing is reset; the branch is simply unchanged.

    • C. Even with the right base, those commits aren't in main.

    • D. PR commit lists are computed from the branches each time.

  10. Question 10Advanced Git and GitHub

    An organization publishes a private container image to ghcr.io/acme/base from repository A. A workflow in repository B tries to pull it with GITHUB_TOKEN and gets 403 Forbidden. What fixes this with the least privilege?

    • A

      Make the image public so that every workflow in every repository can pull it without a token

    • B

      Store an owner's personal access token as a secret in repository B

    • C

      Give repository B the packages: admin permission in its workflow file

    • D

      Grant repository B read access in the package's "Manage Actions access" settings

    Show the answer and explanation

    Answer: D

    The Container registry supports granular permissions. By default GITHUB_TOKEN can work with packages associated with its own repository. To let a workflow in another repository pull the image, add that repository under the package's Actions access settings with read access.

    Why the other options are wrong

    • A. That exposes the image to everyone instead of granting one repository access.

    • B. A long-lived personal token grants far more than this pull needs.

    • C. A workflow cannot grant itself access to a package it was not allowed to use.

Practise all 450 GIT questions

Start with the free 15-question diagnostic. It shows where to focus, and your results carry over if you sign up.

Go to GIT