Infrastructure as Code Flashcards
7 cards from real AZ-400 practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Infrastructure as Code flashcards as text
Which Terraform feature allows you to define reusable infrastructure components with input variables and output values?
Answer: Terraform modules
Terraform modules are self-contained packages of Terraform configuration with defined inputs (variables) and outputs, enabling reuse across projects.
In Azure DevOps, what is the recommended way to store Terraform state files to support team collaboration and state locking?
Answer: Store in Azure Blob Storage with state locking via Azure Storage lease mechanism
Azure Blob Storage with the `azurerm` backend provides remote state storage and uses Azure Storage blob leases to implement state locking, preventing concurrent modifications.
What is the function of `@allowed` decorator in Azure Bicep?
Answer: Defines the set of permissible values for a parameter
The `@allowed` decorator constrains a parameter to only accept values from a specified list, causing deployment validation to fail if an unlisted value is provided.
When implementing IaC in a CI/CD pipeline, what is the purpose of separating `terraform plan` and `terraform apply` into different pipeline stages?
Answer: It enables human review and approval of the planned changes before infrastructure is modified
Separating plan from apply allows teams to review exactly what infrastructure changes will occur and require approval gates before any modifications are made to production.
Which Azure CLI command deploys a Bicep file to a specific resource group?
Answer: az deployment group create --resource-group myRG --template-file main.bicep
`az deployment group create` with `--template-file` accepts both `.json` ARM templates and `.bicep` files for resource group-scoped deployments.
In Terraform, what does the `ignore_changes` lifecycle argument do when specified for a resource attribute?
Answer: Prevents Terraform from ever modifying that attribute after initial creation
`ignore_changes` tells Terraform to ignore drift on specified attributes after initial creation, so external changes to those attributes won't be overwritten on the next apply.
What is the primary purpose of Azure Blueprints in an enterprise IaC strategy?
Answer: Packaging role assignments, policies, resource groups, and ARM templates for repeatable environment governance
Azure Blueprints bundle together policy assignments, RBAC role assignments, resource groups, and ARM templates into a single versioned artifact for consistent environment provisioning.