AZ-400: Designing and Implementing Microsoft DevOps Solutions — Questions and Answers
Question 1: Which Maven scopes are NOT included in the final packaged artifact by default, making them safe for test-only dependencies?
- system and import
- compile and provided
- test and provided (Correct answer)
- compile and runtime
Correct answer: test and provided
Maven 'test' scope dependencies are only on the test classpath and 'provided' scope is expected from the runtime environment, so neither is packaged in the final artifact.
Question 2: Which tool is most commonly used for Static Application Security Testing (SAST) integration in Azure DevOps pipelines?
- Terraform
- SonarQube (Correct answer)
- Selenium
- OWASP ZAP
Correct answer: SonarQube
SonarQube analyzes source code without executing it, identifying security vulnerabilities, bugs, and code smells, and integrates directly into Azure Pipelines as a SAST tool.
Question 3: In Azure DevOps, what is a 'release definition' (classic) equivalent to in YAML pipelines?
- A branch policy in Azure Repos
- An artifact feed in Azure Artifacts
- A deployment group configuration
- A YAML pipeline file with stages defined under the 'stages' key (Correct answer)
Correct answer: A YAML pipeline file with stages defined under the 'stages' key
In YAML pipelines, the stages section with deployment jobs and environments replicates the functionality of a classic release definition with its environments and stages.
Question 4: What happens when you link a variable group to a pipeline but the Azure Key Vault secret has been deleted?
- The variable group is automatically unlinked
- The pipeline run fails when it attempts to fetch the deleted secret (Correct answer)
- The pipeline skips the secret and uses an empty string
- The pipeline uses the last cached value from the previous successful run
Correct answer: The pipeline run fails when it attempts to fetch the deleted secret
If a Key Vault secret is deleted, the pipeline fails at runtime when Azure DevOps attempts to retrieve the missing secret value.
Question 5: What is the purpose of work item linking in Azure DevOps?
- To assign permissions
- To create builds
- To establish relationships and traceability between work items (Correct answer)
- To delete work items
Correct answer: To establish relationships and traceability between work items
Work item linking establishes relationships between items, enabling traceability from requirements through tasks to code changes and tests.
Question 6: Which practice in Agile and DevOps involves team members describing completed work and demonstrating it to stakeholders at the end of a sprint?
- Daily Standup
- Backlog Refinement
- Sprint Retrospective
- Sprint Review (Correct answer)
Correct answer: Sprint Review
The Sprint Review is a collaborative event where the team demonstrates completed work to stakeholders and gathers feedback to inform the backlog.
Question 7: What does 'shift-left security' mean in the context of DevSecOps?
- Integrating security practices earlier in the software development lifecycle (Correct answer)
- Shifting security responsibilities entirely to the operations team
- Moving security testing to the final production stage
- Moving security configurations to the left pane of the Azure portal
Correct answer: Integrating security practices earlier in the software development lifecycle
Shift-left security means integrating security practices and testing earlier in the SDLC so vulnerabilities are caught sooner, reducing the cost and risk of remediation.
Question 8: Which Azure DevOps feature enforces security review by requiring designated approvers before code can be merged into a protected branch?
- Pipeline approval gates
- Branch policies with required reviewers (Correct answer)
- Azure Test Plans required test cases
- Work item state transitions
Correct answer: Branch policies with required reviewers
Branch policies in Azure Repos can mandate that specified security reviewers approve a pull request before the merge is allowed, embedding human security oversight into the workflow.
Question 9: How does the AZ-400 body of knowledge relate to daily professional practice?
- It only applies during certification exams
- It is relevant only for academic research
- It is theoretical and has limited practical application
- It provides the foundational framework that guides decision-making and standard practices (Correct answer)
Correct answer: It provides the foundational framework that guides decision-making and standard practices
The body of knowledge provides the foundational framework of principles, standards, and best practices that professionals use to guide their daily decision-making, ensure consistent quality, and maintain alignment with industry standards.
Question 10: What is a sprint in Azure DevOps?
- A type of build
- A test plan
- A time-boxed iteration for completing a set of work items (Correct answer)
- A deployment stage
Correct answer: A time-boxed iteration for completing a set of work items
A sprint is a fixed-duration iteration during which the team commits to completing a specific set of work items.
Question 11: Which foundational principle is MOST important for success in the Microsoft Azure DevOps Engineer profession?
- Maintaining the minimum requirements for certification
- Maximizing financial returns on every engagement
- Commitment to continuous learning, ethical practice, and quality outcomes (Correct answer)
- Specializing in only one narrow area of practice
Correct answer: Commitment to continuous learning, ethical practice, and quality outcomes
Success in any professional field requires a commitment to continuous learning to stay current, ethical practice to maintain trust and integrity, and a focus on quality outcomes that serve stakeholders and the public interest.
Question 12: Which Go module command downloads all dependencies listed in go.mod and updates go.sum with their cryptographic hashes?
- go mod vendor
- go mod tidy
- go get ./...
- go mod download (Correct answer)
Correct answer: go mod download
'go mod download' downloads all modules in go.mod to the local cache and verifies/updates go.sum with their expected cryptographic checksums.
Question 13: Which Azure Artifacts concept allows you to mark a specific package version as the approved production version, protecting it from retention policy deletion?
- Pinning
- Setting the version as 'stable' in the feed settings
- Tagging the package
- Promoting to a view (e.g., @Release) (Correct answer)
Correct answer: Promoting to a view (e.g., @Release)
Promoting a package version to a view (such as @Prerelease or @Release) marks it as approved for that stage and protects it from automatic deletion by retention policies.
Question 14: What is the purpose of the 'protected' flag on an Azure Pipelines YAML environment?
- It encrypts all variables in the environment automatically
- It restricts the environment to only run on private agents
- It requires pipeline resources like service connections in that environment to pass approval checks
- It prevents the environment from being deleted by non-admins (Correct answer)
Correct answer: It prevents the environment from being deleted by non-admins
Marking an environment as protected restricts deletion and modification to users with the Administrator role, preventing accidental removal of critical environments.
Question 15: Which Log Analytics function allows you to join two tables in a KQL query?
- union
- lookup
- join (Correct answer)
- merge
Correct answer: join
The `join` operator in KQL merges rows from two tables based on matching values in specified columns, similar to SQL JOINs.
Question 16: Which Azure service integrates with Azure DevOps to provide work item creation automatically from Application Insights alert failures?
- Azure Logic Apps
- Azure Automation
- Azure DevOps work item integration in Application Insights (Correct answer)
- Azure Service Bus
Correct answer: Azure DevOps work item integration in Application Insights
Application Insights has native Azure DevOps work item integration that can automatically create work items when specific alert conditions are met.
Question 17: Which Azure DevOps feature allows you to gate a deployment stage until specific work items are linked to the release?
- Deployment slots
- Approval policies
- Release gates with work item query (Correct answer)
- Branch policies
Correct answer: Release gates with work item query
Release gates can query Azure Boards work items so a stage only proceeds when required items are in the correct state.
Question 18: Which framework provides Microsoft's prescriptive security best practices and control mappings specifically for Azure and multi-cloud environments?
- Microsoft Cloud Security Benchmark (MCSB) (Correct answer)
- NIST SP 800-53
- HIPAA Security Rule
- PCI DSS v4.0
Correct answer: Microsoft Cloud Security Benchmark (MCSB)
The Microsoft Cloud Security Benchmark (MCSB) maps Azure security recommendations to common industry standards (NIST, CIS, PCI) and is the primary guidance Microsoft publishes for securing Azure workloads.
Question 19: What is the primary benefit of using Terraform workspaces in a multi-environment IaC strategy?
- They allow multiple teams to edit the same state file simultaneously
- They automatically create Azure resource groups per environment
- They encrypt the Terraform state file at rest
- They enable managing multiple distinct state files from the same configuration (Correct answer)
Correct answer: They enable managing multiple distinct state files from the same configuration
Terraform workspaces maintain separate state files for each workspace, letting the same configuration manage dev, staging, and prod environments independently.
Question 20: Which deployment pattern involves routing production traffic to a new version while using the production data set — but never exposing results to users until manually promoted?
- Canary
- Recreate
- Blue-green
- Shadow (dark launch) deployment (Correct answer)
Correct answer: Shadow (dark launch) deployment
Shadow deployments send real production traffic to the new version silently; responses are discarded and users see only the live service until promotion.
Question 21: A company needs to ensure their Azure release pipeline only deploys during business hours on weekdays. Which feature should they use?
- Scheduled triggers
- Agent pool restrictions
- Deployment conditions with time-based gates (Correct answer)
- Branch filters
Correct answer: Deployment conditions with time-based gates
Deployment conditions allow you to specify time-based restrictions (schedifying allowed deployment windows) to prevent releases outside approved hours.
Question 22: Which deployment strategy in Azure Pipelines YAML should be used to deploy to a percentage of targets first, verify health, then roll out to the rest?
- canary (Correct answer)
- runOnce
- blueGreen
- rolling
Correct answer: canary
The 'canary' deployment strategy in YAML pipelines deploys to a defined percentage of targets first, allows health checks, then proceeds to the remaining targets.
Question 23: Your AKS cluster needs to pull images from Azure Container Registry (ACR) without storing credentials in Kubernetes Secrets. What is the recommended approach?
- Use a service principal password stored in a ConfigMap
- Attach the ACR to the AKS cluster using managed identity integration (Correct answer)
- Store ACR credentials in Azure Key Vault and mount as a volume
- Create an imagePullSecret with the ACR admin credentials
Correct answer: Attach the ACR to the AKS cluster using managed identity integration
Attaching ACR to AKS using managed identity (--attach-acr) grants the kubelet identity the AcrPull role, eliminating the need for stored credentials.
Question 24: In Azure Pipelines, what does a release trigger set to 'Continuous deployment' do?
- Creates a new release automatically whenever the linked artifact is updated (Correct answer)
- Requires manual creation of each release
- Triggers a release on a fixed schedule
- Deploys to all stages simultaneously
Correct answer: Creates a new release automatically whenever the linked artifact is updated
A continuous deployment trigger automatically creates and starts a new release pipeline run whenever a new build artifact is published.
Question 25: A pipeline consuming a private npm package from Azure Artifacts fails with '401 Unauthorized'. The pipeline uses a service connection. What is the most likely fix?
- Switch to a personal access token in the pipeline YAML
- Install the package before the pipeline triggers
- Add the feed URL to .npmrc and authenticate using the pipeline's service connection credential (Correct answer)
- Make the feed public
Correct answer: Add the feed URL to .npmrc and authenticate using the pipeline's service connection credential
You must configure .npmrc with the Azure Artifacts feed URL and use the npm Authenticate task to inject credentials from the service connection.
Question 26: Which configuration is recommended to prevent forked repository pull requests from accessing protected pipeline secrets in Azure Pipelines?
- Store secrets in the pipeline YAML file instead of pipeline variables
- Grant all fork contributors full repository access so they can manage their own secrets
- Disable fork contributions entirely on all repositories
- Configure fork build validation to limit secret access and require manual approval for fork PRs (Correct answer)
Correct answer: Configure fork build validation to limit secret access and require manual approval for fork PRs
Azure Pipelines fork protection settings can prevent secrets from being passed to fork PR builds and require a team member to manually approve the run before it starts.
Question 27: A DevOps team practicing Continuous Delivery wants to ensure every completed user story is deployable. Which Agile practice enforces this?
- Definition of Ready
- Sprint review
- Definition of Done including deployment verification (Correct answer)
- Release planning
Correct answer: Definition of Done including deployment verification
Including deployment verification in the Definition of Done ensures that 'done' means the feature is actually deployable, not just coded.
Question 28: In the context of Azure DevOps and Agile, what is the primary purpose of a Definition of Done (DoD)?
- To define when a sprint ends
- To list acceptance criteria for individual stories
- To establish shared quality standards all work must meet before being considered complete (Correct answer)
- To document release approval requirements
Correct answer: To establish shared quality standards all work must meet before being considered complete
The Definition of Done is a shared agreement on the quality criteria every work item must satisfy before it can be marked as complete.
Question 29: Which Terraform command is used to preview infrastructure changes without applying them?
- terraform plan (Correct answer)
- terraform validate
- terraform refresh
- terraform apply --dry-run
Correct answer: terraform plan
`terraform plan` generates an execution plan showing what changes Terraform will make without actually applying them.
Question 30: A team is using Azure DevOps for a large program with multiple Scrum teams. Which feature helps synchronize dependencies across teams?
- Team dashboards
- Delivery Plans (Correct answer)
- Area paths
- Shared sprint boards
Correct answer: Delivery Plans
Delivery Plans in Azure DevOps provide a cross-team timeline view that highlights work and dependencies across multiple teams and sprints.
Question 31: Which Azure Pipelines artifact type allows a release pipeline to consume packages published to Azure Artifacts feeds?
- GitHub artifact
- Azure Artifacts artifact (Correct answer)
- Container artifact
- Pipeline artifact
Correct answer: Azure Artifacts artifact
The Azure Artifacts artifact source type links a release pipeline to a specific feed and package, enabling versioned package consumption in deployments.
Question 32: Which documentation is essential when working with infrastructure as code in AZ-400?
- Only verbal notes
- General descriptions without specifics
- Detailed technical specifications and as-built diagrams (Correct answer)
- Marketing materials
Correct answer: Detailed technical specifications and as-built diagrams
Detailed technical specifications and as-built diagrams provide the accurate reference information needed for maintenance and troubleshooting.
Question 33: Which task should you use in Azure Pipelines to cache NuGet packages and reduce restore times on repeated builds?
- PublishBuildArtifacts
- NuGetAuthenticate
- Cache (Correct answer)
- DownloadPipelineArtifact
Correct answer: Cache
The Cache task stores and restores directories (such as the NuGet package cache) between pipeline runs using a cache key, reducing download time.
Question 34: What is the MOST effective way for new AZ-400 professionals to build competency in their field?
- Learning entirely through trial and error
- Focusing solely on the most advanced topics
- Studying certification materials exclusively
- Combining formal education, mentored practice, and ongoing professional development (Correct answer)
Correct answer: Combining formal education, mentored practice, and ongoing professional development
Building professional competency requires a multi-faceted approach: formal education provides foundational knowledge, mentored practice develops applied skills under guidance, and ongoing professional development ensures continuous growth and currency in the field.
Question 35: What does 'flaky test' mean, and how should a CI pipeline handle it?
- A test written in a deprecated framework that needs migration
- A test that runs too slowly and should be removed from the pipeline
- A test that consistently fails due to a code bug; it should block the build
- A test that passes and fails non-deterministically; it should be quarantined and tracked separately (Correct answer)
Correct answer: A test that passes and fails non-deterministically; it should be quarantined and tracked separately
Flaky tests produce inconsistent results across identical runs due to timing, environment, or external dependencies, and should be quarantined to prevent false CI failures while being investigated.
Question 36: Which statement BEST describes the relationship between Microsoft Azure DevOps Engineer certification requirements and industry evolution?
- Requirements become less stringent over time
- Changes only occur when government mandates new requirements
- Certification requirements never change once established
- Requirements evolve periodically to reflect advances in knowledge, technology, and practice standards (Correct answer)
Correct answer: Requirements evolve periodically to reflect advances in knowledge, technology, and practice standards
Certification requirements evolve to keep pace with advances in professional knowledge, technological developments, and changes in practice standards. This ensures that certified professionals remain current and competent in a changing professional landscape.
Question 37: What is the best practice for maintaining infrastructure as code performance over time?
- Upgrade all equipment annually
- Implement scheduled preventive maintenance (Correct answer)
- Outsource all maintenance
- Wait for failures before acting
Correct answer: Implement scheduled preventive maintenance
Scheduled preventive maintenance catches potential issues before they cause failures, maintaining reliability and extending equipment life.
Question 38: Which statement correctly describes the `output` variable type in Azure Pipelines?
- Output variables are defined using the `output:` keyword in the variables section
- Output variables are automatically available in all subsequent stages without any mapping
- Output variables replace secret variables once published
- A step can set an output variable using `##vso[task.setvariable variable=name;isOutput=true]value` (Correct answer)
Correct answer: A step can set an output variable using `##vso[task.setvariable variable=name;isOutput=true]value`
Steps set output variables using the logging command `##vso[task.setvariable variable=name;isOutput=true]value`, making them available to downstream jobs.
Question 39: What distinguishes a Microsoft Azure DevOps Engineer certified professional from a non-certified practitioner?
- Certified professionals always have more years of experience
- Certification validates competency through standardized assessment against established benchmarks (Correct answer)
- Certified professionals exclusively work in larger organizations
- There is no meaningful difference in competency
Correct answer: Certification validates competency through standardized assessment against established benchmarks
Certification provides objective validation of competency through standardized assessment. While non-certified practitioners may be skilled, certification offers verified evidence that a professional meets established benchmarks for knowledge and performance.
Question 40: A team's lead time has been increasing over several sprints. Which Azure Boards tool best helps them diagnose where delays are accumulating in their workflow?
- Sprint burndown chart
- Velocity chart
- Cumulative Flow Diagram (Correct answer)
- Test plans dashboard
Correct answer: Cumulative Flow Diagram
The Cumulative Flow Diagram reveals where work is piling up by showing the width of each workflow band widening, indicating a bottleneck stage.
Question 41: Which Azure Policy effect automatically deploys a resource or configuration to bring a non-compliant resource into compliance?
- Deny
- Audit
- Append
- DeployIfNotExists (Correct answer)
Correct answer: DeployIfNotExists
The DeployIfNotExists effect triggers a remediation deployment when a resource is found to be missing required configurations, automatically restoring compliance.
Question 42: Your team wants to enforce that all NuGet packages used in a solution come from the corporate Azure Artifacts feed only, blocking direct access to nuget.org. How do you enforce this?
- Set a pipeline variable NUGET_PACKAGES to the corporate feed URL
- Configure the feed with upstream sources disabled and distribute a NuGet.Config that points only to the corporate feed (Correct answer)
- Remove nuget.org from developer machines' NuGet.Config
- Use a conditional step in the pipeline to fail if nuget.org is referenced
Correct answer: Configure the feed with upstream sources disabled and distribute a NuGet.Config that points only to the corporate feed
Distributing a NuGet.Config that lists only the corporate feed and disabling upstream sources ensures all package resolution goes through the controlled feed.
Question 43: In Application Insights, what does the 'sampling' feature primarily help with?
- Reducing telemetry cost and storage while retaining statistical accuracy (Correct answer)
- Filtering out error telemetry
- Encrypting telemetry data
- Increasing telemetry volume
Correct answer: Reducing telemetry cost and storage while retaining statistical accuracy
Sampling reduces the volume of telemetry sent and stored to control costs while preserving statistical representativeness of the data.
Question 44: What is the purpose of the 'postRouteTraffic' lifecycle hook in an Azure Pipelines canary strategy?
- To run tests before any traffic is routed to the canary
- To permanently remove the old version
- To execute steps after canary traffic has been routed, typically for monitoring or validation (Correct answer)
- To scale up the canary to 100%
Correct answer: To execute steps after canary traffic has been routed, typically for monitoring or validation
postRouteTraffic runs after traffic is shifted to the canary, allowing teams to run smoke tests or observe metrics before deciding to roll out or roll back.
Question 45: What is a conditional expression in Azure DevOps YAML pipelines?
- A logic statement that controls whether a step runs based on conditions (Correct answer)
- A deployment target
- A variable type
- A build error
Correct answer: A logic statement that controls whether a step runs based on conditions
Conditional expressions evaluate conditions at runtime to determine whether specific pipeline steps or stages should execute.
Question 46: What is the PRIMARY purpose of obtaining AZ-400 certification in Microsoft Azure DevOps Engineer?
- To demonstrate verified competency and adherence to professional standards (Correct answer)
- To guarantee employment in the field
- To satisfy a personal achievement goal
- To bypass educational requirements
Correct answer: To demonstrate verified competency and adherence to professional standards
Professional certification demonstrates that an individual has met established competency standards through verified assessment. It provides assurance to employers, clients, and the public that the certified professional possesses the knowledge and skills required for competent practice.
Question 47: A pipeline must download a secure configuration file from Azure Key Vault at deploy time. Which integration approach is recommended?
- Use the Azure Key Vault task to fetch secrets into pipeline variables (Correct answer)
- Use a service principal token in a deployment script
- Hardcode the values in the YAML file
- Store secrets in pipeline variables marked as secret
Correct answer: Use the Azure Key Vault task to fetch secrets into pipeline variables
The Azure Key Vault task retrieves secrets at runtime and maps them to pipeline variables without exposing them in YAML.
Question 48: A team wants to ensure user stories have clear, testable acceptance criteria before sprint planning. Which Agile concept enforces this?
- Release Criteria
- Definition of Done
- Definition of Ready (Correct answer)
- Sprint Goal
Correct answer: Definition of Ready
The Definition of Ready specifies conditions a backlog item must meet (including acceptance criteria) before the team can commit to it in sprint planning.
Question 49: Your team wants every production deployment to be traceable to a specific work item. Which Azure DevOps feature supports this requirement?
- Deployment history linked to commits and work items (Correct answer)
- Release gates
- Service hooks
- Artifact retention
Correct answer: Deployment history linked to commits and work items
Azure Pipelines automatically associates commits and linked work items to each deployment recorded in the release history.
Question 50: What is the primary purpose of Software Composition Analysis (SCA) in a DevSecOps pipeline?
- Monitoring runtime application behavior for anomalies
- Identifying vulnerabilities in third-party and open-source dependencies (Correct answer)
- Testing application APIs for authentication flaws
- Scanning infrastructure templates for misconfigurations
Correct answer: Identifying vulnerabilities in third-party and open-source dependencies
SCA scans open-source and third-party libraries used in an application to identify known CVEs, outdated packages, and license compliance issues.
Question 51: Which foundational principle is MOST important for success in the Microsoft Azure DevOps Engineer profession?
- Specializing in only one narrow area of practice
- Maximizing financial returns on every engagement
- Commitment to continuous learning, ethical practice, and quality outcomes (Correct answer)
- Maintaining the minimum requirements for certification
Correct answer: Commitment to continuous learning, ethical practice, and quality outcomes
Success in any professional field requires a commitment to continuous learning to stay current, ethical practice to maintain trust and integrity, and a focus on quality outcomes that serve stakeholders and the public interest.
Question 52: You have a Contoso Azure DevOps organization and a Contoso Azure subscription with an Azure virtual machine scale set named VMSS1 that is setup for autoscaling. <br> <br> You create a web app named Appl with Azure DevOps and deploy it to VMSS1. Appl is heavily utilized and has weekly usage patterns that change. <br> <br> You must propose a technique for detecting an unusual increase in the number of unsuccessful requests to Appl. The solution must require the least amount of administrative effort. <br> <br> What should your advice include?
- an Azure Monitor alert that uses an Azure Log Analytics query
- an Azure Service Health alert
- the Failures feature in Azure Application Insights
- the Smart Detection feature m Azure Application Insights (Correct answer)
Correct answer: the Smart Detection feature m Azure Application Insights
The Smart Detection feature in Azure Application Insights automatically identifies unusual performance patterns and failures in your application. It uses machine learning to learn the normal behavior of your application and proactively alerts you to significant deviations, such as an unusual increase in unsuccessful requests. This approach requires minimal administrative effort as it doesn't necessitate manual configuration of thresholds or complex alert rules.
Question 53: A team wants to block merges to 'main' unless two approvers have reviewed the PR AND the CI build passes. Which combination of Azure DevOps branch policies achieves this?
- Commit message validation + work item linking policy
- Branch lock + merge strategy policy
- Status check policy + comment resolution policy
- Minimum reviewer count policy + build validation policy (Correct answer)
Correct answer: Minimum reviewer count policy + build validation policy
Combining the minimum number of reviewers policy with the build validation policy enforces both human approval and automated build success as merge prerequisites.
Question 54: Which professional attribute is most valued in monitoring and feedback within the AZ-400 field?
- Avoiding challenging situations
- Prioritizing personal convenience
- Working in isolation
- Accountability and commitment to standards (Correct answer)
Correct answer: Accountability and commitment to standards
Accountability and commitment to professional standards build trust and ensure consistent, high-quality practice.
Question 55: During a canary deployment in AKS, you want to route exactly 20% of traffic to the new version. Which Kubernetes resource controls this traffic split?
- PersistentVolumeClaim
- Ingress with NGINX annotations or a service mesh weight (Correct answer)
- ResourceQuota
- ConfigMap
Correct answer: Ingress with NGINX annotations or a service mesh weight
NGINX Ingress canary annotations or a service mesh (like Istio) VirtualService weights control the percentage of traffic routed to each deployment.
Question 56: A team wishes to use Azure Pipelines to deliver applications in a continuous manner. The applications must be installed on a collection of Azure virtual machines. <br> <br> Which of the following methods can be used to get the virtual machines ready?
- Release gates
- Azure Pipeline Agent extension (Correct answer)
- Deployment groups
- Release builds
Correct answer: Azure Pipeline Agent extension
To enable Azure Pipelines to deploy applications to a collection of Azure virtual machines, an Azure Pipelines agent must be installed on each target VM. This agent software acts as a communication bridge, allowing the pipeline to execute tasks and scripts directly on the VM. Installing and configuring this agent (which can be thought of as extending the VM's capabilities for pipelines) is the fundamental step to 'get the virtual machines ready' for continuous delivery.
Question 57: Your build pipeline restores NuGet packages but you want to ensure the resolved versions exactly match the checked-in packages.lock.json. Which dotnet CLI flag enforces this?
- --force-evaluate
- --use-lock-file
- --no-dependencies
- --locked-mode (Correct answer)
Correct answer: --locked-mode
'dotnet restore --locked-mode' fails the restore if the lock file is out of date or if the resolved packages don't match the lock file, ensuring reproducible builds.
Question 58: In Azure, you have a Microsoft ASP.NET Core web app that is accessed from all over the world. <br> Once every five minutes, run a URL ping test and create an alert if the web app is inaccessible in particular Azure regions. The solution should take as little time as possible to build. <br> What are your options?
- Write an Azure function and deploy the function to the specific regions
- Create an Azure Application Insights availability test and alert (Correct answer)
- Create an Azure Service Health alert for the specific regions
- Create an Azure Monitor Availability metric and alert.
Correct answer: Create an Azure Application Insights availability test and alert
To run a URL ping test every five minutes and alert if a web app is inaccessible in specific Azure regions with minimal build time, creating an Azure Application Insights availability test and alert is the best option. Application Insights allows you to configure multi-step web tests or simple URL ping tests from various global locations. These tests automatically monitor your web app's availability and performance, and you can easily set up alerts to notify you of any failures in specific regions.
AZ-400: Designing and Implementing Microsoft DevOps Solutions
The AZ-400 exam measures your ability to design and implement DevOps practices for version control, compliance, infrastructure as code, configuration management, build, release, and testing using Azure technologies. It is required for the Microsoft Certified: DevOps Engineer Expert certification.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds