โ† All AZ-400 Flashcard Decks

Dependency Management Flashcards

7 cards from real AZ-400 practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Dependency Management flashcards as text
  1. Your team wants to prevent developers from publishing packages with known critical CVEs to Azure Artifacts. Which feature should you enable?

    Answer: Artifact policies with vulnerability scanning

    Artifact policies with vulnerability scanning (via Microsoft Defender for DevOps or integrated tools) can block publishing of packages containing critical CVEs.

  2. A developer runs 'npm audit' in their pipeline and it reports high-severity vulnerabilities. Which Azure DevOps pipeline task provides built-in npm audit integration?

    Answer: npm task with 'custom' command set to 'audit'

    The built-in npm pipeline task supports running 'npm audit' by setting the command to 'custom' and specifying 'audit' as the custom command.

  3. You want NuGet packages published to Azure Artifacts to be automatically deleted after 30 days unless promoted to the 'Release' view. Which feature handles this?

    Answer: Retention policies

    Retention policies in Azure Artifacts automatically delete older package versions based on age or version count, with promotions to views protecting packages from deletion.

  4. Which Maven scopes are NOT included in the final packaged artifact by default, making them safe for test-only dependencies?

    Answer: test and provided

    Maven 'test' scope dependencies are only on the test classpath and 'provided' scope is expected from the runtime environment, so neither is packaged in the final artifact.

  5. Your organization uses Azure Artifacts with upstream sources. A developer requests a package version that exists in the upstream but not locally. What happens?

    Answer: The package is fetched from upstream, cached locally, and returned

    Azure Artifacts upstream sources fetch the requested package from the upstream source, save a cached copy in your feed, and return it to the client transparently.

  6. A pipeline consuming a private npm package from Azure Artifacts fails with '401 Unauthorized'. The pipeline uses a service connection. What is the most likely fix?

    Answer: Add the feed URL to .npmrc and authenticate using the pipeline's service connection credential

    You must configure .npmrc with the Azure Artifacts feed URL and use the npm Authenticate task to inject credentials from the service connection.

  7. When configuring an Azure Artifacts feed to use npmjs.com as an upstream source, what is the default behavior when a package exists in both the feed and upstream?

    Answer: The locally stored (feed) version is returned without contacting upstream

    Azure Artifacts always serves the locally stored copy first; the upstream is only contacted if the package or version is not yet cached in the feed.