โ† All AZ-400 Flashcard Decks

Container and Microservices Deployment Flashcards

7 cards from real AZ-400 practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Container and Microservices Deployment flashcards as text
  1. You need to store sensitive database connection strings for a containerized app in AKS. What is the most secure method to inject these at runtime?

    Answer: Mount secrets from Azure Key Vault using the Secrets Store CSI Driver

    The Secrets Store CSI Driver mounts Key Vault secrets directly into pods as volumes or environment variables without storing them in etcd as Kubernetes Secrets.

  2. When using Azure Container Instances (ACI) for burst capacity alongside AKS, which component enables AKS pods to be scheduled onto ACI nodes transparently?

    Answer: Virtual Kubelet / AKS virtual nodes

    Virtual Kubelet (implemented as AKS virtual nodes) registers ACI as a node in the cluster, allowing the scheduler to place pods on ACI using standard Kubernetes node selectors.

  3. In a microservices architecture on AKS, you need service discovery without using a service mesh. Which Kubernetes-native mechanism handles DNS-based discovery?

    Answer: CoreDNS resolving ClusterIP Service names using the format ..svc.cluster.local

    CoreDNS in AKS automatically creates DNS records for each Service, enabling pods to discover services by their fully qualified DNS name within the cluster.

  4. Your pipeline must build a container image for both linux/amd64 and linux/arm64 architectures from a single Dockerfile. Which Docker feature enables this?

    Answer: docker buildx build --platform linux/amd64,linux/arm64 with BuildKit

    Docker Buildx with BuildKit supports multi-platform builds using the --platform flag, producing a single multi-arch manifest image from one build command.

  5. A microservice Deployment in AKS needs to complete in-flight requests before a pod is terminated during rolling updates. Which pod configuration achieves this?

    Answer: Add a preStop lifecycle hook with a sleep and set terminationGracePeriodSeconds appropriately

    A preStop sleep hook delays SIGTERM until Kubernetes removes the pod from endpoints, combined with terminationGracePeriodSeconds long enough for in-flight requests to complete.

  6. In Azure DevOps, which environment resource type is used to represent an AKS namespace as a deployment target with built-in deployment history and approvals?

    Answer: Kubernetes resource in an Azure DevOps Environment

    Adding a Kubernetes resource to an Azure DevOps Environment enables deployment tracking, audit history, and approval gates for deployments targeting a specific AKS namespace.

  7. When configuring Horizontal Pod Autoscaler (HPA) in AKS, what happens if both minReplicas and maxReplicas are set to the same value?

    Answer: The HPA maintains a fixed replica count and effectively disables autoscaling

    When minReplicas equals maxReplicas, the HPA cannot scale up or down and keeps the replica count fixed at that value, making autoscaling non-functional.