Dependency Management Flashcards
7 cards from real AZ-400 practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Dependency Management flashcards as text
You want to automatically update outdated npm dependencies and open pull requests for each update. Which tool integrates natively with Azure DevOps for this?
Answer: Renovate Bot configured with an Azure DevOps provider
Renovate Bot supports Azure DevOps natively as a platform, scanning repos for outdated dependencies and automatically opening PRs with version bumps.
Which Azure Artifacts concept allows you to mark a specific package version as the approved production version, protecting it from retention policy deletion?
Answer: Promoting to a view (e.g., @Release)
Promoting a package version to a view (such as @Prerelease or @Release) marks it as approved for that stage and protects it from automatic deletion by retention policies.
Your pipeline publishes a Maven package to Azure Artifacts. Which authentication method does Microsoft recommend for Maven pipelines in Azure DevOps?
Answer: The MavenAuthenticate task with a service connection
The MavenAuthenticate pipeline task injects credentials from a service connection into Maven's settings.xml at runtime, which is Microsoft's recommended approach.
A vulnerability is found in a transitive dependency (a dependency of a dependency). Which approach is best for mitigating it in an npm project without waiting for the direct dependency to update?
Answer: Use the 'overrides' field in package.json to force a specific version of the transitive dependency
The 'overrides' field in package.json (npm v8.3+) forces a specific version of a transitive dependency across the entire dependency tree, patching the vulnerability immediately.
In Azure Artifacts, what is the purpose of a 'project-scoped' feed versus an 'organization-scoped' feed?
Answer: Project-scoped feeds are visible only within the project; organization-scoped feeds are accessible to all projects in the organization
Project-scoped feeds are associated with a specific Azure DevOps project and inherit its permissions, while organization-scoped feeds are accessible to all projects in the organization.
You need to publish a pre-release NuGet package from a feature branch pipeline. Which versioning suffix convention indicates a pre-release package per SemVer?
Answer: 2.0.0-beta.1
SemVer pre-release versions use a hyphen suffix (e.g., 2.0.0-beta.1), which NuGet and Azure Artifacts recognize as a pre-release version lower in precedence than 2.0.0.
When configuring Dependabot for an Azure DevOps repository, where must the dependabot.yml configuration file be placed?
Answer: /.github/dependabot.yml
Even when using Dependabot with Azure DevOps (via a compatibility layer or GitHub Actions bridge), the configuration file must be placed at /.github/dependabot.yml.