Security and Compliance Flashcards
7 cards from real AZ-400 practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Security and Compliance flashcards as text
What does the OWASP Top 10 represent in the context of application security?
Answer: A list of the 10 most critical web application security risks
The OWASP Top 10 is a standard awareness document published by the Open Web Application Security Project listing the 10 most critical security risks to web applications.
In Azure Pipelines, what is the recommended way to prevent a secret variable's value from appearing in pipeline logs?
Answer: Mark the variable as secret in the pipeline variable settings
Marking a pipeline variable as secret causes Azure Pipelines to mask its value in all logs, preventing accidental exposure of credentials.
Which Microsoft security product integrates with Azure DevOps repositories to provide code scanning, secret scanning, and dependency review?
Answer: GitHub Advanced Security
GitHub Advanced Security (GHAS) provides code scanning (SAST), secret scanning, and dependency review and can be enabled on Azure DevOps repositories as well as GitHub.
What is the purpose of a security gate configured in an Azure DevOps release pipeline?
Answer: To automatically pause or reject releases that fail security compliance checks
Security gates evaluate compliance conditions (e.g., calling a security API or checking Azure Policy compliance) and halt a release if the criteria are not met.
Which Azure service provides unified security posture management and gives resources a 'Secure Score' to prioritize security improvements?
Answer: Microsoft Defender for Cloud
Microsoft Defender for Cloud (formerly Azure Security Center) aggregates security recommendations across resources and surfaces them as a Secure Score to help teams prioritize improvements.
What does the principle of least privilege require when configuring service connections and pipeline permissions in Azure DevOps?
Answer: Granting only the minimum permissions necessary to perform the required tasks
Least privilege means each pipeline, service connection, and user should have only the permissions they need—nothing more—reducing the blast radius of a compromise.
Which Azure DevOps settings allow administrators to restrict which users can queue builds, manage environments, and access pipeline secrets?
Answer: Pipeline permissions and environment security settings
Azure Pipelines and Environments each have their own permission settings where administrators can grant or restrict queue, manage, and use access per user or group.