Pipeline Variables and Templates Flashcards
7 cards from real AZ-400 practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Pipeline Variables and Templates flashcards as text
An organization wants to mandate that all pipelines include a security scanning job. Which Azure DevOps feature best enforces this?
Answer: Required pipeline templates via the `extends` keyword and protected template resources
Required templates configured with `extends` and protected as a resource force every consuming pipeline to include the mandated jobs.
What is the correct way to iterate over an `object` parameter (a list) inside a YAML template using `each`?
Answer: ${{ each item in parameters.list }}:
The `${{ each item in parameters.list }}:` template expression iterates over an object parameter list to generate repeated YAML blocks.
A YAML pipeline sets a variable with `isReadonly: true`. What is the effect?
Answer: The variable cannot be overridden at queue time by users
Setting `isReadonly: true` on a variable prevents users from overriding its value when manually triggering a pipeline run.
Which approach correctly maps an output variable from job A to job B within the same stage?
Answer: In job B's variables section: `$[dependencies.JobA.outputs['stepA.myVar']]`
Within the same stage, cross-job output variables are referenced using `$[dependencies.JobName.outputs['stepName.varName']]`.
What happens when you link a variable group to a pipeline but the Azure Key Vault secret has been deleted?
Answer: The pipeline run fails when it attempts to fetch the deleted secret
If a Key Vault secret is deleted, the pipeline fails at runtime when Azure DevOps attempts to retrieve the missing secret value.
Which keyword in a YAML template file defines the expected inputs that callers must or may provide?
Answer: parameters:
The `parameters:` section at the top of a YAML template file declares the typed inputs that consuming pipelines can or must pass.
A pipeline variable contains a JSON string. How can a Bash step safely extract a specific field from it?
Answer: Echo the variable into `jq` within the Bash step: `echo '$(jsonVar)' | jq -r '.field'`
Within a Bash step, you can echo the macro-expanded variable value and pipe it through `jq` to extract individual JSON fields.