Dependency Management & Infrastructure as Code Flashcards
7 cards from real AZ-400 practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Dependency Management & Infrastructure as Code flashcards as text
A security audit finds that Terraform state files stored in Azure Blob Storage contain sensitive data in plaintext. What is the recommended mitigation?
Answer: Enable Azure Storage encryption with customer-managed keys and restrict access via RBAC
Enabling Azure Storage encryption with customer-managed keys ensures state data is encrypted at rest, while RBAC restricts who can read the state file.
You need to share a private npm package across multiple Azure DevOps projects within the same organization. What is the most efficient approach?
Answer: Use a single organization-scoped Azure Artifacts feed with project visibility settings
An organization-scoped Azure Artifacts feed can be shared across all projects in the organization, eliminating redundant feeds and publish steps.
What is the purpose of the `dependsOn` property in an Azure Resource Manager (ARM) template?
Answer: It defines explicit resource deployment ordering when implicit ordering cannot be determined
`dependsOn` explicitly declares that one resource must be fully deployed before another begins, used when ARM cannot infer the dependency from template references.
A Terraform plan shows that a resource will be destroyed and recreated due to a change. Which Terraform meta-argument can prevent recreation by updating in-place if the provider supports it?
Answer: ignore_changes
`ignore_changes` tells Terraform to disregard changes to specified attributes, preventing a destroy-and-recreate cycle when those attributes change outside of Terraform.
Which Azure DevOps gate or check would you configure to pause a pipeline stage until a work item linked to the release is in 'Resolved' state?
Answer: Query work items gate
The Query Work Items gate runs an Azure Boards query and only allows the pipeline to proceed if the query results meet specified criteria, such as all linked items being Resolved.
Your organization requires that all Bicep-deployed resources have a specific 'CostCenter' tag. A developer deploys without the tag. Which Azure Policy effect modifies the deployment to add the missing tag automatically?
Answer: Modify
The Modify effect adds or updates tags on resources during deployment, automatically inserting the required 'CostCenter' tag if missing.
When configuring upstream sources in Azure Artifacts, what is the maximum number of official upstream sources you can add to a single feed?
Answer: 25
Azure Artifacts supports up to 25 upstream sources per feed, covering public package registries like NuGet.org, npmjs.com, PyPI, and Maven Central.