โ† All AZ-400 Flashcard Decks

Infrastructure as Code Flashcards

7 cards from real AZ-400 practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Infrastructure as Code flashcards as text
  1. Which Terraform feature allows you to define reusable infrastructure components with input variables and output values?

    Answer: Terraform modules

    Terraform modules are self-contained packages of Terraform configuration with defined inputs (variables) and outputs, enabling reuse across projects.

  2. In Azure DevOps, what is the recommended way to store Terraform state files to support team collaboration and state locking?

    Answer: Store in Azure Blob Storage with state locking via Azure Storage lease mechanism

    Azure Blob Storage with the `azurerm` backend provides remote state storage and uses Azure Storage blob leases to implement state locking, preventing concurrent modifications.

  3. What is the function of `@allowed` decorator in Azure Bicep?

    Answer: Defines the set of permissible values for a parameter

    The `@allowed` decorator constrains a parameter to only accept values from a specified list, causing deployment validation to fail if an unlisted value is provided.

  4. When implementing IaC in a CI/CD pipeline, what is the purpose of separating `terraform plan` and `terraform apply` into different pipeline stages?

    Answer: It enables human review and approval of the planned changes before infrastructure is modified

    Separating plan from apply allows teams to review exactly what infrastructure changes will occur and require approval gates before any modifications are made to production.

  5. Which Azure CLI command deploys a Bicep file to a specific resource group?

    Answer: az deployment group create --resource-group myRG --template-file main.bicep

    `az deployment group create` with `--template-file` accepts both `.json` ARM templates and `.bicep` files for resource group-scoped deployments.

  6. In Terraform, what does the `ignore_changes` lifecycle argument do when specified for a resource attribute?

    Answer: Prevents Terraform from ever modifying that attribute after initial creation

    `ignore_changes` tells Terraform to ignore drift on specified attributes after initial creation, so external changes to those attributes won't be overwritten on the next apply.

  7. What is the primary purpose of Azure Blueprints in an enterprise IaC strategy?

    Answer: Packaging role assignments, policies, resource groups, and ARM templates for repeatable environment governance

    Azure Blueprints bundle together policy assignments, RBAC role assignments, resource groups, and ARM templates into a single versioned artifact for consistent environment provisioning.