โ† All AZ-400 Flashcard Decks

Dependency Management Flashcards

7 cards from real AZ-400 practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Dependency Management flashcards as text
  1. You want to automatically update outdated npm dependencies and open pull requests for each update. Which tool integrates natively with Azure DevOps for this?

    Answer: Renovate Bot configured with an Azure DevOps provider

    Renovate Bot supports Azure DevOps natively as a platform, scanning repos for outdated dependencies and automatically opening PRs with version bumps.

  2. Which Azure Artifacts concept allows you to mark a specific package version as the approved production version, protecting it from retention policy deletion?

    Answer: Promoting to a view (e.g., @Release)

    Promoting a package version to a view (such as @Prerelease or @Release) marks it as approved for that stage and protects it from automatic deletion by retention policies.

  3. Your pipeline publishes a Maven package to Azure Artifacts. Which authentication method does Microsoft recommend for Maven pipelines in Azure DevOps?

    Answer: The MavenAuthenticate task with a service connection

    The MavenAuthenticate pipeline task injects credentials from a service connection into Maven's settings.xml at runtime, which is Microsoft's recommended approach.

  4. A vulnerability is found in a transitive dependency (a dependency of a dependency). Which approach is best for mitigating it in an npm project without waiting for the direct dependency to update?

    Answer: Use the 'overrides' field in package.json to force a specific version of the transitive dependency

    The 'overrides' field in package.json (npm v8.3+) forces a specific version of a transitive dependency across the entire dependency tree, patching the vulnerability immediately.

  5. In Azure Artifacts, what is the purpose of a 'project-scoped' feed versus an 'organization-scoped' feed?

    Answer: Project-scoped feeds are visible only within the project; organization-scoped feeds are accessible to all projects in the organization

    Project-scoped feeds are associated with a specific Azure DevOps project and inherit its permissions, while organization-scoped feeds are accessible to all projects in the organization.

  6. You need to publish a pre-release NuGet package from a feature branch pipeline. Which versioning suffix convention indicates a pre-release package per SemVer?

    Answer: 2.0.0-beta.1

    SemVer pre-release versions use a hyphen suffix (e.g., 2.0.0-beta.1), which NuGet and Azure Artifacts recognize as a pre-release version lower in precedence than 2.0.0.

  7. When configuring Dependabot for an Azure DevOps repository, where must the dependabot.yml configuration file be placed?

    Answer: /.github/dependabot.yml

    Even when using Dependabot with Azure DevOps (via a compatibility layer or GitHub Actions bridge), the configuration file must be placed at /.github/dependabot.yml.