โ† All AZ-400 Flashcard Decks

Continuous Delivery Flashcards

7 cards from real AZ-400 practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Continuous Delivery flashcards as text
  1. Your organization requires that only signed container images can be deployed to production AKS clusters. Which Azure service enforces this policy?

    Answer: Azure Container Registry content trust

    ACR content trust uses Docker Notary to sign images, and AKS can be configured to reject unsigned images at admission.

  2. A YAML pipeline stage depends on two other stages completing successfully. How should this dependency be declared?

    Answer: List both stage names under 'dependsOn'

    The 'dependsOn' keyword in a stage definition accepts a list of stage names that must complete before this stage runs.

  3. Which feature of Azure Pipelines environments enables you to restrict which branches can deploy to a protected environment like production?

    Answer: Branch control check

    The branch control check on an environment allows deployments only from pipelines running on specified branches (e.g., 'main').

  4. When using Azure Pipelines with GitHub repositories, which trigger type initiates a CD pipeline run when a pull request is merged to main?

    Answer: CI trigger on the main branch

    A CI trigger set on the 'main' branch fires when commits are pushed to main, which is the result of a merged pull request.

  5. A release pipeline must deploy a database schema migration before deploying the application. How should this sequencing be enforced?

    Answer: Place the database migration in a prior stage with 'dependsOn' on the app stage

    Placing the migration in a separate earlier stage and declaring 'dependsOn' ensures the migration completes before the application stage starts.

  6. Which Azure DevOps concept tracks deployment records, approvals, and health checks for a group of resources such as a Kubernetes namespace?

    Answer: Environment

    An Azure DevOps environment represents a deployment target (like a K8s namespace or VM group) and records all deployments, approvals, and checks against it.

  7. A team stores Terraform state in Azure Blob Storage. During CD, the pipeline must acquire a state lock to prevent concurrent deployments. What is the correct approach?

    Answer: Rely on Azure Blob Storage lease-based locking built into the azurerm backend

    The Terraform azurerm backend natively uses Azure Blob Storage leases for state locking, preventing concurrent Terraform operations.