正解:A
To allow Microsoft Defender for Cloud to assess GitHub repositories, you must first add GitHub as an environment in the Defender for Cloud portal.
Defender for Cloud supports connecting to external DevOps environments - including GitHub and Azure DevOps - to assess code repositories for security issues such as exposed secrets, vulnerable dependencies, or misconfigurations.
The connection process begins by selecting "Add environment" and then choosing GitHub. After authorization via OAuth to your GitHub account, Defender for Cloud scans the repositories to provide security posture assessments and recommendations.
Other options are not correct because:
* Enable security policies: Used for configuring compliance and standards within subscriptions, not external code repositories.
* Enable integrations: General connector setup, but GitHub integration specifically starts through Add environment.
* Enable a plan: Plans (e.g., Defender for Servers, Defender for App Service) control billing and coverage scope, not onboarding.