Designing and Implementing Microsoft DevOps Solutions Free Sample Questions

20 free sample questions250 in the full practice test

Try simulator

AZ-400 Sample Questions

  1. Question 1

    A financial services company is implementing a new DevOps strategy. They are using Azure DevOps for work item tracking and Azure Repos for their private source code. For compliance reasons, every commit pushed to the main branch must be linked to an approved work item in Azure Boards. The team lead wants to enforce this policy automatically and reject any pushes that do not comply. Which source control feature should be configured in Azure Repos?

    Answer and explanation

    Correct answer: B

    The most effective and automated way to enforce that commits are linked to work items before they are merged into a protected branch like main is by using a branch policy. This policy can be configured on the main branch to require work item linking on pull requests, effectively preventing direct pushes and ensuring traceability for all changes.

  2. Question 2

    A DevOps team is tasked with monitoring a suite of microservices deployed to Azure Kubernetes Service (AKS). They need to collect detailed performance metrics, dependency maps, and trace transactions across services to quickly identify bottlenecks. The solution must integrate seamlessly with Azure Monitor and support custom telemetry. Which Azure service is specifically designed for this level of application performance monitoring?

    Answer and explanation

    Correct answer: C

    Application Insights is the Application Performance Management (APM) feature of Azure Monitor. It is specifically designed to monitor live applications, automatically detect performance anomalies, and includes powerful analytics tools like Application Map for dependency visualization and distributed tracing to diagnose issues across microservices.

  3. Question 3

    Multiple answers

    A security team wants to implement a robust secret management strategy for their Azure Pipelines. They have the following requirements:

    1. Secrets must be stored centrally and securely outside of Azure DevOps.
    2. Pipelines must be able to retrieve secrets at runtime without exposing them in logs.
    3. Access to secrets should be granted based on the pipeline's identity, not on user credentials.

    Which combination of Azure services and features best meets these requirements? (Select TWO)

    Answer and explanation

    Correct answers: A, C

    Azure Key Vault is the primary Azure service for centralized, secure storage of secrets, keys, and certificates. This directly addresses the requirement to store secrets outside of Azure DevOps.

    Using a Service Connection configured with a Managed Identity allows the pipeline to authenticate to Azure resources like Key Vault using its own identity, managed by Azure AD. This fulfills the requirement of granting access based on the pipeline's identity without using static credentials like service principals with secrets.

  4. Question 4

    A project manager at a large enterprise is concerned about the team's release cadence and efficiency. They want to track key DORA (DevOps Research and Assessment) metrics, specifically Lead Time for Changes and Deployment Frequency. The team uses Azure Boards for work items and Azure Pipelines for CI/CD. Where can the project manager most effectively visualize these metrics in a continuously updated dashboard?

    Answer and explanation

    Correct answer: C

    Azure DevOps Analytics provides built-in widgets specifically for DORA metrics like Lead Time and Deployment Frequency. These can be added to a team Dashboard, offering a centralized, continuously updated view that pulls data directly from Azure Boards and Pipelines, which is the most effective and integrated solution.

  5. Question 5

    A development team is building a containerized application and using a YAML pipeline in Azure Pipelines to build and push the image to Azure Container Registry (ACR). During a security review, it was mandated that no container image with 'High' or 'Critical' vulnerabilities should be pushed to the production ACR instance. What is the most integrated and automated way to enforce this within the Azure ecosystem?

    Answer and explanation

    Correct answer: B

    This is the most integrated solution. Microsoft Defender for Containers scans images upon push to ACR. By combining this with an Azure Policy for ACR that denies pushes based on the scan findings (e.g., has 'High' severity vulnerabilities), the requirement is enforced at the registry level, providing a robust, automated control that cannot be bypassed by pipeline configurations.

  6. Question 6

    A team is adopting trunk-based development using GitHub. To maintain code quality and prevent broken builds, they want to enforce that all pull requests targeting the main branch must pass a series of checks before they can be merged. These checks include a successful build, a minimum code coverage percentage, and a security scan. What GitHub feature should be configured on the main branch to enforce these requirements?

    Answer and explanation

    Correct answer: C

    Branch protection rules are the specific GitHub feature designed to enforce workflows for one or more branches. You can configure rules that require status checks (like builds, tests, and scans from GitHub Actions) to pass before a pull request can be merged into the protected branch. This directly addresses all the stated requirements.

  7. Question 7

    A DevOps engineer needs to write a Kusto Query Language (KQL) query in Log Analytics to investigate performance issues. The goal is to find the average request duration for all failed requests (resultCode starts with '5') in the requests table over the last 24 hours, summarized into 1-hour intervals. Which KQL query correctly accomplishes this?

    Answer and explanation

    Correct answer: B

    This query is correct. where timestamp > ago(24h) filters for the last day. resultCode startswith '5' correctly identifies server-side failures. summarize avg(duration) calculates the average duration. by bin(timestamp, 1h) correctly groups the results into 1-hour time bins.

  8. Question 8

    A manufacturing company is modernizing its application deployment. The primary goal is to minimize downtime and risk when deploying new versions of their critical inventory management web app, which is hosted on Azure App Service. They want to route a small percentage of live traffic to the new version for a period of time to monitor its performance and stability before rolling it out to all users. Which deployment strategy should they implement?

    Answer and explanation

    Correct answer: C

    The canary release strategy is specifically designed for routing a small subset of production traffic to a new version. In Azure App Service, this is perfectly implemented using deployment slots. One can deploy the new version to a staging slot and then use the traffic routing feature to direct a specified percentage (e.g., 10%) of traffic to that slot, allowing for monitoring before a full rollout.

  9. Question 9

    True or False: When using GitHub Advanced Security, secret scanning is limited to detecting secrets only in the default branch of a repository.

    Answer and explanation

    Correct answer: B

    False. GitHub Advanced Security's secret scanning scans the entire Git history on all branches in a repository for secrets, not just the default branch. It also scans pull requests as they are created.

  10. Question 10

    A DevOps team manages multiple projects, each with its own Azure Pipeline. To ensure consistency and reduce redundant code, they want to create a reusable component that defines a sequence of steps for running integration tests. This component should be easily versioned and shared across different pipelines. Which Azure Pipelines feature is best suited for this purpose?

    Answer and explanation

    Correct answer: C

    YAML templates are the ideal solution for creating versionable and reusable pipeline components. A template can define a set of steps, jobs, or even entire stages that can be imported into multiple pipelines. Since templates are stored as YAML files in a repository, they can be versioned, managed via pull requests, and shared, providing the highest level of reusability and maintainability.

Register free to unlock 10 more sample questions

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 250 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon