← All AZ-400 Flashcard Decks

Security and Compliance Flashcards

7 cards from real AZ-400 practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Security and Compliance flashcards as text
  1. What does the OWASP Top 10 represent in the context of application security?

    Answer: A list of the 10 most critical web application security risks

    The OWASP Top 10 is a standard awareness document published by the Open Web Application Security Project listing the 10 most critical security risks to web applications.

  2. In Azure Pipelines, what is the recommended way to prevent a secret variable's value from appearing in pipeline logs?

    Answer: Mark the variable as secret in the pipeline variable settings

    Marking a pipeline variable as secret causes Azure Pipelines to mask its value in all logs, preventing accidental exposure of credentials.

  3. Which Microsoft security product integrates with Azure DevOps repositories to provide code scanning, secret scanning, and dependency review?

    Answer: GitHub Advanced Security

    GitHub Advanced Security (GHAS) provides code scanning (SAST), secret scanning, and dependency review and can be enabled on Azure DevOps repositories as well as GitHub.

  4. What is the purpose of a security gate configured in an Azure DevOps release pipeline?

    Answer: To automatically pause or reject releases that fail security compliance checks

    Security gates evaluate compliance conditions (e.g., calling a security API or checking Azure Policy compliance) and halt a release if the criteria are not met.

  5. Which Azure service provides unified security posture management and gives resources a 'Secure Score' to prioritize security improvements?

    Answer: Microsoft Defender for Cloud

    Microsoft Defender for Cloud (formerly Azure Security Center) aggregates security recommendations across resources and surfaces them as a Secure Score to help teams prioritize improvements.

  6. What does the principle of least privilege require when configuring service connections and pipeline permissions in Azure DevOps?

    Answer: Granting only the minimum permissions necessary to perform the required tasks

    Least privilege means each pipeline, service connection, and user should have only the permissions they need—nothing more—reducing the blast radius of a compromise.

  7. Which Azure DevOps settings allow administrators to restrict which users can queue builds, manage environments, and access pipeline secrets?

    Answer: Pipeline permissions and environment security settings

    Azure Pipelines and Environments each have their own permission settings where administrators can grant or restrict queue, manage, and use access per user or group.