โ† All AZ-400 Flashcard Decks

Monitoring, Feedback & Security Flashcards

7 cards from real AZ-400 practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Monitoring, Feedback & Security flashcards as text
  1. Which OWASP-aligned practice should be integrated into an Azure DevOps pipeline to catch injection vulnerabilities in application code before release?

    Answer: Static Application Security Testing (SAST) using a tool like SonarQube or Checkmarx

    SAST tools analyze source code for injection flaws and other OWASP vulnerabilities during the build stage before code reaches production.

  2. Your team uses Azure Boards to capture post-incident learnings. Which work item type is most appropriate for tracking a recurring reliability improvement?

    Answer: Bug

    In Azure Boards, a Bug work item type is used to track reliability defects and recurring production issues including post-incident action items.

  3. A pipeline runs DAST scans against a staging environment. The scan tool reports findings as a SARIF file. How should you surface these results in Azure DevOps?

    Answer: Upload the SARIF file using the PublishTestResults task with format SARIF

    The PublishTestResults task supports SARIF format, which makes security findings visible natively in the Azure DevOps pipeline results UI.

  4. You need Application Insights to track business KPIs such as 'completed checkouts per hour' alongside technical telemetry. Which SDK method enables this?

    Answer: trackEvent() with custom properties and measurements

    trackEvent() allows you to emit named custom events with properties and measurements, making it ideal for business-level KPI tracking.

  5. Which Azure Policy effect should you use to audit non-compliant resources without blocking their creation during initial rollout of a new security standard?

    Answer: Audit

    The Audit effect flags non-compliant resources in the compliance report without preventing their creation, making it safe for initial rollout.

  6. A security team needs to ensure no pipeline can access Azure resources using a long-lived secret stored in a variable group. Which approach eliminates long-lived secrets?

    Answer: Use an Azure DevOps service connection with workload identity federation (OIDC)

    Workload identity federation allows pipelines to authenticate to Azure using short-lived OIDC tokens, eliminating the need for stored client secrets.

  7. You want to create an alert that fires when the 95th percentile response time for a web API exceeds 2 seconds over the last 10 minutes. Which alert type is most appropriate?

    Answer: Log alert using a KQL query on Application Insights requests table with percentile aggregation

    A Log alert with a KQL query using the percentile() function on the requests table provides precise 95th-percentile response time alerting.