Dependency Management Flashcards
7 cards from real AZ-400 practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Dependency Management flashcards as text
Your build pipeline restores NuGet packages but you want to ensure the resolved versions exactly match the checked-in packages.lock.json. Which dotnet CLI flag enforces this?
Answer: --locked-mode
'dotnet restore --locked-mode' fails the restore if the lock file is out of date or if the resolved packages don't match the lock file, ensuring reproducible builds.
A package published to Azure Artifacts is found to be malicious. What is the fastest way to prevent it from being installed by any team member?
Answer: Delete the specific package version from the feed
Deleting the specific package version from the Azure Artifacts feed immediately prevents any new installs of that version while leaving all other packages unaffected.
Which Go module command downloads all dependencies listed in go.mod and updates go.sum with their cryptographic hashes?
Answer: go mod download
'go mod download' downloads all modules in go.mod to the local cache and verifies/updates go.sum with their expected cryptographic checksums.
Your organization wants to use Azure Artifacts as a universal package registry for binaries that are not language-specific (e.g., compiled CLI tools). Which package type should you use?
Answer: Universal Packages
Azure Artifacts Universal Packages support any file type and size, making them ideal for distributing compiled binaries, scripts, or other non-language-specific artifacts.
A security policy requires that all packages in Azure Artifacts feeds must originate from approved upstream sources only. Which setting enforces this at the feed level?
Answer: Set 'upstream sources' to include only approved registries and block direct publish from unapproved sources
Configuring upstream sources to include only approved registries and restricting direct publish permissions ensures all packages flow through vetted sources.
In an Azure DevOps pipeline, you want to fail the build if any direct NuGet dependency has a known HIGH or CRITICAL vulnerability. Which integration achieves this most directly?
Answer: OWASP Dependency-Check task with a CVSS threshold configured to fail on HIGH/CRITICAL
The OWASP Dependency-Check Azure DevOps task scans NuGet packages and can be configured with a CVSS score threshold to fail the pipeline when HIGH or CRITICAL vulnerabilities are found.
Your team uses Azure Artifacts with multiple feeds across different projects. To reduce duplication, you want packages from Feed A to be available in Feed B without republishing. What should you configure?
Answer: Add Feed A as an upstream source in Feed B
Adding Feed A as an upstream source in Feed B allows Feed B consumers to transparently access and cache packages from Feed A without manual republishing.