โ† All AZ-400 Flashcard Decks

Container and Microservices Deployment Flashcards

7 cards from real AZ-400 practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Container and Microservices Deployment flashcards as text
  1. You need to implement blue-green deployments for a microservice in AKS. Which Kubernetes resource strategy best achieves this?

    Answer: Use two separate Deployments with a Service selector toggling between labels

    Blue-green deployments in Kubernetes use two Deployments (blue and green) and switch the Service selector label to route traffic to the new version instantly.

  2. Your AKS cluster needs to pull images from Azure Container Registry (ACR) without storing credentials in Kubernetes Secrets. What is the recommended approach?

    Answer: Attach the ACR to the AKS cluster using managed identity integration

    Attaching ACR to AKS using managed identity (--attach-acr) grants the kubelet identity the AcrPull role, eliminating the need for stored credentials.

  3. A microservice in AKS is experiencing CPU throttling under load. Which HPA metric source allows scaling based on custom application metrics from Azure Monitor?

    Answer: External metrics adapter using Azure Monitor metrics

    The Azure Monitor metrics adapter exposes custom and external metrics to the HPA, enabling scaling based on application-specific telemetry.

  4. When configuring a multi-stage Azure Pipeline to build and push a Docker image, which built-in variable contains the unique identifier suitable for tagging the image per build?

    Answer: $(Build.BuildId)

    $(Build.BuildId) is an auto-incrementing integer unique per build, commonly used as a Docker image tag to ensure traceability.

  5. You want to enforce that only images from your ACR registry are deployed into a specific AKS namespace. Which Azure Policy built-in achieves this?

    Answer: Kubernetes cluster containers should only use allowed images

    The 'allowed images' policy uses OPA Gatekeeper to restrict container images to an approved registry pattern, preventing unauthorized images from running.

  6. In a Helm chart deployment pipeline, which command applies a new chart version to an existing release WITHOUT deleting and recreating resources when possible?

    Answer: helm upgrade

    helm upgrade performs an in-place update of an existing Helm release, patching resources rather than recreating them unless necessary.

  7. A container in your AKS pod fails its readiness probe repeatedly. What is the immediate effect on traffic routing?

    Answer: The pod is removed from Service endpoints until the probe passes

    A failing readiness probe causes Kubernetes to remove the pod from the Service's endpoint slice, stopping traffic from reaching it without restarting the container.