Dependency Management Flashcards
7 cards from real AZ-400 practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Dependency Management flashcards as text
You need to share a common library across multiple Azure DevOps projects without duplicating source code. What is the recommended Azure Artifacts approach?
Answer: Publish the library as a versioned package to a shared Azure Artifacts feed
Publishing the library as a versioned package to a shared Azure Artifacts feed is the recommended approach for reuse, versioning, and dependency management across projects.
Which pip command generates a requirements.txt file that pins every installed package to its exact current version?
Answer: pip freeze > requirements.txt
'pip freeze' outputs all installed packages and their exact versions in requirements.txt format, enabling reproducible installs.
Your team wants to enforce that all NuGet packages used in a solution come from the corporate Azure Artifacts feed only, blocking direct access to nuget.org. How do you enforce this?
Answer: Configure the feed with upstream sources disabled and distribute a NuGet.Config that points only to the corporate feed
Distributing a NuGet.Config that lists only the corporate feed and disabling upstream sources ensures all package resolution goes through the controlled feed.
In Gradle, which configuration is used for dependencies required only at compile time and NOT needed at runtime?
Answer: compileOnly
'compileOnly' in Gradle marks dependencies that are needed to compile the code but should not be included in the runtime classpath or packaged artifact.
Your organization wants to track open-source license compliance for all NuGet packages. Which Azure DevOps marketplace extension is most commonly used for this?
Answer: WhiteSource (Mend) Bolt
WhiteSource Bolt (now Mend Bolt) is a free Azure DevOps extension that scans NuGet, npm, and other packages for open-source license compliance and vulnerabilities.
When using semantic versioning in Azure Artifacts, what does a version change from 2.3.1 to 2.4.0 indicate?
Answer: A backward-compatible new feature was added
In semantic versioning (MAJOR.MINOR.PATCH), incrementing the MINOR version (2.3.x → 2.4.0) indicates new backward-compatible functionality was added.
A pipeline uses 'dotnet restore' but packages are repeatedly downloaded from the internet on every run despite no changes. How do you add caching to fix this?
Answer: Use the 'Cache' pipeline task with the NuGet packages directory and a key based on the packages.lock.json hash
The Cache pipeline task stores and restores the NuGet packages directory using a cache key derived from the lock file hash, skipping downloads when dependencies haven't changed.