Skip to content

AZ-400 Practice Questions

Prepare for AZ-400 with more than an answer.

250 questions in the full set20 sample questionsUpdated Aug 21, 2026
Exam fee
$165 USD
Level
Expert
Valid for
1 year
Domains covered on the exam 5
  1. Design and implement processes and communications12.5%
  2. Design and implement a source control strategy12.5%
  3. Design and implement build and release pipelines52.5%
  4. Develop a security and compliance plan12.5%
  5. Implement an instrumentation strategy7.5%
  1. 1

    A team is migrating their classic UI-based release pipelines in Azure DevOps to multi-stage YAML pipelines. They heavily use release gates to query Azure Monitor alerts and ensure system health before promoting a release to the next stage. How can this same functionality be implemented in a YAML pipeline?

    Show answer details

    Correct answer: D

    In YAML pipelines, the functionality of classic release gates is replaced by 'Checks' on 'Environments'. You can define an environment (e.g., 'Production') and configure checks on it, such as 'Invoke Azure Function' or 'Query Azure Monitor alerts'. A deployment job targeting this environment will only run after all configured checks have passed successfully.

  2. 2

    A developer needs to revert a specific commit (abc1234) from the main branch that introduced a bug, but wants to keep the commit in the branch history for auditing purposes. The commit is not the most recent one. Which Git command should be used to achieve this?

    Show answer details

    Correct answer: C

    The git revert command is used to create a new commit that undoes the changes made in a previous commit. This is the correct approach because it doesn't alter the existing project history, making it a safe operation for shared branches. The original buggy commit remains in the history, and a new commit is added that reverses its effects.

  3. 3

    A company is using GitHub and wants to automate the analysis of vulnerabilities in their open-source dependencies. They need a tool that automatically creates pull requests to upgrade packages to non-vulnerable versions. Which GitHub feature should they configure?

    Show answer details

    Correct answer: C

    Dependabot is a GitHub feature specifically designed to find and fix vulnerabilities in dependencies. It can be configured to monitor dependency files and automatically create pull requests to update dependencies to secure versions, addressing the requirement perfectly.

  4. 4

    An organization is using both GitHub for source control and Azure DevOps for work item tracking and CI/CD pipelines. They want to establish traceability between GitHub commits and Azure Boards work items. Which two actions are required to enable developers to link commits to work items? (Select TWO)

    Show answer details

    Correct answer: A, C

    The Azure Boards app for GitHub is the primary mechanism that establishes the connection between the two platforms, allowing them to communicate and link artifacts.

    Once the integration is established, developers use the AB# syntax in their commit messages. This special mention is recognized by the integration and automatically links the commit to the specified Azure Boards work item.

  5. 5

    A team uses a multi-stage YAML pipeline to deploy an application to Staging and Production environments. The deployment to Production requires an explicit sign-off from the project manager. The following diagram shows the pipeline structure. How should this approval be configured?

    flowchart LR Build --> Test Test --> Deploy_Staging Deploy_Staging --> Approval{Approval?} Approval -->|Yes| Deploy_Production Approval -->|No| Stop([End])

    Show answer details

    Correct answer: C

    In YAML pipelines, manual approvals are configured as 'Checks' on an 'Environment'. By creating a 'Production' environment and adding an 'Approvals' check, you can specify users or groups (like the project manager) who must approve any deployment job that targets that environment. This pauses the pipeline until the approval is granted.

  6. 6

    A financial services company is implementing a new DevOps strategy. They are using Azure DevOps for work item tracking and Azure Repos for their private source code. For compliance reasons, every commit pushed to the main branch must be linked to an approved work item in Azure Boards. The team lead wants to enforce this policy automatically and reject any pushes that do not comply. Which source control feature should be configured in Azure Repos?

    Show answer details

    Correct answer: B

    The most effective and automated way to enforce that commits are linked to work items before they are merged into a protected branch like main is by using a branch policy. This policy can be configured on the main branch to require work item linking on pull requests, effectively preventing direct pushes and ensuring traceability for all changes.

  7. 7

    A DevOps team is tasked with monitoring a suite of microservices deployed to Azure Kubernetes Service (AKS). They need to collect detailed performance metrics, dependency maps, and trace transactions across services to quickly identify bottlenecks. The solution must integrate seamlessly with Azure Monitor and support custom telemetry. Which Azure service is specifically designed for this level of application performance monitoring?

    Show answer details

    Correct answer: C

    Application Insights is the Application Performance Management (APM) feature of Azure Monitor. It is specifically designed to monitor live applications, automatically detect performance anomalies, and includes powerful analytics tools like Application Map for dependency visualization and distributed tracing to diagnose issues across microservices.

  8. 8

    A security team wants to implement a robust secret management strategy for their Azure Pipelines. They have the following requirements:

    1. Secrets must be stored centrally and securely outside of Azure DevOps.
    2. Pipelines must be able to retrieve secrets at runtime without exposing them in logs.
    3. Access to secrets should be granted based on the pipeline's identity, not on user credentials.

    Which combination of Azure services and features best meets these requirements? (Select TWO)

    Show answer details

    Correct answer: A, C

    Azure Key Vault is the primary Azure service for centralized, secure storage of secrets, keys, and certificates. This directly addresses the requirement to store secrets outside of Azure DevOps.

    Using a Service Connection configured with a Managed Identity allows the pipeline to authenticate to Azure resources like Key Vault using its own identity, managed by Azure AD. This fulfills the requirement of granting access based on the pipeline's identity without using static credentials like service principals with secrets.

  9. 9

    A project manager at a large enterprise is concerned about the team's release cadence and efficiency. They want to track key DORA (DevOps Research and Assessment) metrics, specifically Lead Time for Changes and Deployment Frequency. The team uses Azure Boards for work items and Azure Pipelines for CI/CD. Where can the project manager most effectively visualize these metrics in a continuously updated dashboard?

    Show answer details

    Correct answer: C

    Azure DevOps Analytics provides built-in widgets specifically for DORA metrics like Lead Time and Deployment Frequency. These can be added to a team Dashboard, offering a centralized, continuously updated view that pulls data directly from Azure Boards and Pipelines, which is the most effective and integrated solution.

  10. 10

    A development team is building a containerized application and using a YAML pipeline in Azure Pipelines to build and push the image to Azure Container Registry (ACR). During a security review, it was mandated that no container image with 'High' or 'Critical' vulnerabilities should be pushed to the production ACR instance. What is the most integrated and automated way to enforce this within the Azure ecosystem?

    Show answer details

    Correct answer: B

    This is the most integrated solution. Microsoft Defender for Containers scans images upon push to ACR. By combining this with an Azure Policy for ACR that denies pushes based on the scan findings (e.g., has 'High' severity vulnerabilities), the requirement is enforced at the registry level, providing a robust, automated control that cannot be bypassed by pipeline configurations.

Create an account to continue.