โ† All AZ-400 Flashcard Decks

Dependency Management & Infrastructure as Code Flashcards

7 cards from real AZ-400 practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Dependency Management & Infrastructure as Code flashcards as text
  1. Your team wants to prevent developers from using packages with known critical vulnerabilities in Azure Artifacts. Which feature should you enable?

    Answer: Azure Defender for DevOps vulnerability scanning with block policies

    Azure Defender for DevOps integrates with Azure Artifacts to scan packages and can enforce policies that block builds when critical vulnerabilities are detected.

  2. A Terraform configuration uses a module stored in a private Azure Repos Git repository. Which authentication method should be used in the module source URL?

    Answer: SSH key with git SSH protocol

    SSH key authentication with the git SSH protocol is the recommended approach for Terraform to access private Azure Repos Git repositories without embedding credentials.

  3. You need to enforce that all Bicep deployments use a specific API version for a resource type. Which Azure Policy effect achieves this at deployment time?

    Answer: Deny

    The Deny effect blocks deployments that do not meet the policy condition, ensuring non-compliant API versions cannot be deployed.

  4. Which command converts an existing ARM template to a Bicep file?

    Answer: az bicep decompile --file template.json

    The `az bicep decompile --file template.json` command converts an existing ARM JSON template into a Bicep file.

  5. A pipeline publishes a NuGet package to Azure Artifacts on every build, causing many patch versions. You want to publish only when the version in the .csproj changes. Which approach is most efficient?

    Answer: Use a pipeline condition comparing the current version tag to the last published version

    A pipeline condition that checks whether the current version differs from the latest published version ensures packages are only published on actual version changes.

  6. You are using Terraform Cloud as a remote backend with Azure Pipelines. The pipeline needs to apply infrastructure changes. What is the recommended way to authenticate Terraform Cloud from the pipeline?

    Answer: Store the Terraform Cloud API token in an Azure Key Vault secret and reference it via a pipeline variable group

    Storing the Terraform Cloud API token in Azure Key Vault and referencing it through a pipeline variable group is the recommended secure approach.

  7. When using Azure Artifacts upstream sources, what happens when a package is requested that exists both upstream and in the local feed?

    Answer: The local feed version is served and upstream is not queried

    When a package exists in the local feed, Azure Artifacts serves that cached version without querying upstream, providing speed and reliability.