Compliance & Governance Flashcards
7 cards from real AZ-400 practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Compliance & Governance flashcards as text
What is the primary benefit of integrating Azure Key Vault with Azure Pipelines for secrets management?
Answer: It allows pipelines to retrieve sensitive values at runtime without hardcoding them in pipeline code or plain-text variables
Azure Key Vault integration allows secrets to be fetched at runtime, preventing sensitive values like passwords and connection strings from being stored in pipeline code or plain-text variable groups.
In compliance-focused Azure DevOps implementations, why should service connections used for development environments be kept separate from those used for production?
Answer: Separation enforces least-privilege access and prevents development pipelines from accidentally modifying production resources
Separating service connections by environment enforces the principle of least privilege, ensuring development or test pipelines cannot access or modify production infrastructure.
What Azure DevOps capability enables end-to-end traceability from requirements to deployment by linking commits, builds, and releases to specific work items?
Answer: Work item traceability through linked commits, builds, and deployments
Azure DevOps provides end-to-end traceability by linking commits, builds, and releases back to work items, creating a full audit trail from requirement through to production deployment.
What does the concept of 'immutable artifacts' ensure in a compliance-focused DevOps pipeline?
Answer: The exact binary tested in one environment is promoted and deployed to all subsequent environments unchanged
Immutable artifacts ensure the exact package tested in a lower environment is the same one promoted to production, providing verifiable consistency and a clear compliance audit trail.
What Azure DevOps setting controls which users can create, manage, and run pipelines within a project?
Answer: Pipeline permissions combined with Azure DevOps RBAC roles
Azure DevOps uses role-based access control (RBAC) combined with pipeline-level permissions to control who can create, edit, queue, and administer pipelines within a project.
Which Azure service or tooling can scan Infrastructure as Code (IaC) templates such as ARM, Bicep, or Terraform files for security misconfigurations before deployment?
Answer: Microsoft Defender for DevOps with IaC scanning
Microsoft Defender for DevOps provides IaC scanning capabilities that identify security misconfigurations in templates before they are deployed, supporting shift-left security governance.
Which Azure DevOps governance mechanism ensures that only pipelines explicitly listed in a resource's approval list can consume that resource, such as a production environment or shared service connection?
Answer: Pipeline resource authorization (allowlist-based access control)
Pipeline resource authorization uses an explicit allowlist to ensure only pre-approved pipelines can access sensitive resources, preventing unauthorized pipelines from using production environments or service connections.