โ† All AZ-400 Flashcard Decks

Security and Compliance Flashcards

7 cards from real AZ-400 practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Security and Compliance flashcards as text
  1. Which Azure service should you use to store and manage secrets, keys, and certificates referenced in Azure Pipelines?

    Answer: Azure Key Vault

    Azure Key Vault is the designated service for securely storing and managing secrets, keys, and certificates that can be referenced in Azure Pipelines using variable groups or task steps.

  2. What does 'shift-left security' mean in the context of DevSecOps?

    Answer: Integrating security practices earlier in the software development lifecycle

    Shift-left security means integrating security practices and testing earlier in the SDLC so vulnerabilities are caught sooner, reducing the cost and risk of remediation.

  3. Which tool is most commonly used for Static Application Security Testing (SAST) integration in Azure DevOps pipelines?

    Answer: SonarQube

    SonarQube analyzes source code without executing it, identifying security vulnerabilities, bugs, and code smells, and integrates directly into Azure Pipelines as a SAST tool.

  4. What Azure feature allows you to define governance rules that Azure resources must comply with, and can block non-compliant deployments?

    Answer: Azure Policy

    Azure Policy lets you create and assign policies that enforce organizational rules on resources; deployments that violate a Deny-effect policy are blocked automatically.

  5. Which type of security scanning detects vulnerabilities in a running web application by simulating real attacks against it?

    Answer: Dynamic Application Security Testing (DAST)

    DAST tests a running application from the outside by simulating attacks, finding runtime vulnerabilities such as SQL injection and XSS that static analysis cannot detect.

  6. What is the primary purpose of Software Composition Analysis (SCA) in a DevSecOps pipeline?

    Answer: Identifying vulnerabilities in third-party and open-source dependencies

    SCA scans open-source and third-party libraries used in an application to identify known CVEs, outdated packages, and license compliance issues.

  7. Which Azure DevOps feature enforces security review by requiring designated approvers before code can be merged into a protected branch?

    Answer: Branch policies with required reviewers

    Branch policies in Azure Repos can mandate that specified security reviewers approve a pull request before the merge is allowed, embedding human security oversight into the workflow.