Basic Information of AZ-400 Exam

The AZ-400 exam is also known as the Microsoft Azure DevOps solution exam. This exam is ideal for DevOps professionals involved in process, technology, and collaboration among people. The purpose of the AZ-400 exam is to verify the candidates’ skills in fulfilling this responsibility and providing services and products that meet user needs and business goals. There are four different languages for the exam, such as English, Japanese, Korean and Simplified Chinese. The registration fee for the AZ-400 exam is US$165. This is all the basic information I can give you about the AZ-400 exam.

AZ-400 Exam Mandatory Prerequisites

As shown in the image below:

Designing and Implementing Microsoft DevOps Solutions

You are configuring the settings of a new Git repository in Azure Repos.
You need to ensure that pull requests in a branch meet the following criteria before they are merged:
Committed code must compile successfully.
Pull requests must have a Quality Gate status of Passed in SonarCloud.
Which policy type should you configure for each requirement? To answer, drag the appropriate policy types to the
correct requirements. Each policy type may be used once, more than once, or not at all. You may need to drag the split
between panes or scroll to view content.
NOTE: Each correct selection is worth one point.
Microsoft-technet AZ 400 exam questions-q1

Box 1: A check-in policy
Administrators of Team Foundation version control can add check-in policy requirements. These check-in policies
require the user to take actions when they conduct a check-in to source control.
By default, the following check-in policy types are available:
Builds Requires that the last build was successful before a check-in.
Code Analysis Requires that code analysis is run before check-in.
Work Items Requires that one or more work items be associated with the check-in.
Box 2: Build policy
Reference: https://docs.microsoft.com/en-us/azure/devops/repos/tfvc/add-check-policies

You need to deploy Azure Kubernetes Service (AKS) to host an application. The solution must meet the following
Containers must only be published internally.
AKS clusters must be able to create and manage containers in Azure.
What should you use for each requirement? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Hot Area:

Microsoft-technet AZ 400 exam questions-q2

Box 1: Azure Container Registry Azure services like Azure Container Registry (ACR) and Azure Container Instances
(ACI) can be used and connected from independent container orchestrators like kubernetes (k8s). You can set up a
custom ACR and connect it to an existing k8s cluster to ensure images will be pulled from the private container registry
instead of the public docker hub.
Box 2: An Azure service principal When you\\’re using Azure Container Registry (ACR) with Azure Kubernetes Service
(AKS), an authentication mechanism needs to be established. You can set up AKS and ACR integration during the initial
creation of your AKS cluster. To allow an AKS cluster to interact with ACR, an Azure Active Directory service principal is
References: https://thorsten-hans.com/how-to-use-private-azure-container-registry-with-kubernetes

You have an Azure subscription that contains resources in several resource groups. You need to design a monitoring
strategy that will provide a consolidated view. The solution must support the following requirements:
Support role-based access control (RBAQ by using Azure Active Directory (Azure AD) identities.
Include visuals from Azure Monitor that are generated by using the Kusto query language.
Support documentation written in markdown.
Use the latest data available for each visual. What should you use to create the consolidated view?
A. Azure Data Explorer
B. Azure dashboards
C. Azure Monitor
D. Microsoft Power Bl
Correct Answer: B

Your company has an Azure DevOps project,
The source code for the project is stored in an on-premises repository and uses on an on-premises build server.
You plan to use Azure DevOps to control the build process on the build server by using a self-hosted agent.
You need to implement the self-hosted agent.
You download and install the agent on the build server.
Which two actions should you perform next? Each correct answer presents part of the solution.
A. From Azure, create a shared access signature (SAS).
B. From the build server, create a certificate, and then upload the certificate to Azure Storage.
C. From the build server, create a certificate, and then upload the certificate to Azure Key Vault.
D. From DevOps, create a personal access token (PAT).
E. From the build server, run config.cmd.
Correct Answer: BE
B: Make sure you install your self-signed ssl server certificate into the OS certificate store.
E: When you have a self-signed SSL certificate for your on-premises TFS server, make sure to configure the Git we shipped to allow that self-signed SSL certificate.
Enable git to use SChannel during configure with 2.129.0 or higher version agent Pass –gituseschannel during agent
configuration./config.cmd –gituseschannel Reference: https://docs.microsoft.com/en-us/azure/devops/pipelines/agents/certificate

During a code review, you discover many quality issues. Many modules contain unused variables and empty catch
You need to recommend a solution to improve the quality of the code.
What should you recommend?
A. In a Grunt build task, select Enabled from Control Options.
B. In a Maven build task, select Run PMD.
C. In a Xcode build task, select Use xcpretty from Advanced.
D. In a Gradle build task, select Run Checkstyle.
Correct Answer: B
PMD is a source code analyzer. It finds common programming flaws like unused variables, empty catch blocks,
unnecessary object creation, and so forth.
There is an Apache Maven PMD Plugin which allows you to automatically run the PMD code analysis tool on your
project\\’s source code and generate a site report with its results.
Incorrect Answers:
C: xcpretty is a fast and flexible formatter for xcodebuild. References: https://pmd.github.io/

DRAG DROP You are configuring an Azure DevOps deployment pipeline. The deployed application will authenticate to
a web service by using a secret stored in an Azure key vault. You need to use the secret in the deployment pipeline.
Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions
to the answer area and arrange them in the correct order.
Select and Place:

Microsoft-technet AZ 400 exam questions-q6

You have a multi-tier application that has an Azure Web Apps front end and an Azure SQL Database back end.
You need to recommend a solution to capture and store telemetry data. The solution must meet the following
Support using ad-hoc queries to identify baselines.
Trigger alerts when metrics in the baseline are exceeded.
Store application and database metrics in a central location. What should you include in the recommendation?
A. Azure Event Hubs
B. Azure SQL Database Intelligent Insights
C. Azure Application Insights
D. Azure Log Analytics
Correct Answer: D
Azure Platform as a Service (PaaS) resources, like Azure SQL and Web Sites (Web Apps), can emit performance
metrics data natively to Log Analytics.
The Premium plan will retain up to 12 months of data, giving you an excellent baseline ability.
There are two options available in the Azure portal for analyzing data stored in Log analytics and for creating queries for
ad hoc analysis.
Incorrect Answers:
B: Intelligent Insights analyzes database performance by comparing the database workload from the last hour with the
past seven-day baseline workload. However, we need to handle application metrics as well. References:

Your company has a project in Azure DevOps.
You plan to create a release pipeline that will deploy resources by using Azure Resource Manager templates. The
templates will reference secrets stored in Azure Key Vault.
You need to recommend a solution for accessing the secrets stored in the key vault during deployments. The solution
must use the principle of least privilege.
What should you include in the recommendation? To answer, drag the appropriate configurations to the correct targets.
Each configuration may be used once, more than once, or not at all. You may need to drag the split bar between panes
or scroll to view content.
NOTE: Each correct selection is worth one point.
Select and Place:

Microsoft-technet AZ 400 exam questions-q8

Management plane access control uses RBAC.
The management plane consists of operations that affect the key vault itself, such as:
Creating or deleting a key vault.
Getting a list of vaults in a subscription.
Retrieving Key Vault properties (such as SKU and tags).
Setting Key Vault access policies that control user and application access to keys and secrets.
References: https://docs.microsoft.com/en-us/azure/azure-resource-manager/resource-manager-tutorial-use-key-vault

You have an Azure DevOps organization named Contoso, an Azure DevOps project named Project1, an Azure
subscription named Sub1, and an Azure key vault named vault1.
You need to ensure that you can reference the values of the secrets stored in vault1 in all the pipelines of Project1. The
solution must prevent the values from being stored in the pipelines.
What should you do?
A. Create a variable group in Project1.
B. Add a secure file to Project1.
C. Modify the security settings of the pipelines.
D. Configure the security policy of Contoso.
Correct Answer: A
Use a variable group to store values that you want to control and make available across multiple pipelines.
References: https://docs.microsoft.com/en-us/azure/devops/pipelines/library/variable-groups

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains
a unique solution that might meet the stated goals. Some question sets might have more than one correct solution,
others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not
appear in the review screen.
Your company has a project in Azure DevOps for a new web application.
You need to ensure that when code is checked in, a build runs automatically.
Solution: From the Pre-deployment conditions settings of the release pipeline, you select Batch changes while a build is
in progress.
Does this meet the goal?
A. Yes
B. No
Correct Answer: B
Instead, In Visual Designer, you enable continuous integration (CI) by:
Select the Triggers tab.
Enable Continuous integration.
References: https://docs.microsoft.com/en-us/azure/devops/pipelines/get-started-designer

You have a private GitHub repository.
You need to display the commit status of the repository on Azure Boards.
What should you do first?
A. Create a GitHub action in GitHub.
B. Add the Azure Pipelines app to the GitHub repository.
C. Configure multi-factor authentication (MFA) for your GitHub account.
D. Add the Azure Boards app to the repository.
Correct Answer: B

You administer an Azure DevOps project that includes package feeds.
You need to ensure that developers can unlist and deprecate packages. The solution must use the principle of least
Which access level should you grant to the developers?
A. Collaborator
B. Contributor
C. Owner
Correct Answer: B
Feeds have four levels of access: Owners, Contributors, Collaborators, and Readers. Owners can add any type of
identity-individuals, teams, and groups-to any access level.

Microsoft-technet AZ 400 exam questions-q12

Reference: https://docs.microsoft.com/en-us/azure/devops/artifacts/feeds/feed-permissions

Your company uses the following resources:
Windows Server 2019 container images hosted in an Azure Container Registry
Azure virtual machines that run the latest version of Ubuntu An Azure
Log Analytics workspace Azure Active Directory (Azure AD)
An Azure key vault
For which two resources can you receive vulnerability assessments in Azure Security Center?
Each correct answer presents part of the solution.
A. the Azure Log Analytics workspace
B. the Azure key vault
C. the Azure virtual machines that run the latest version of Ubuntu
D. Azure Active Directory (Azure AD)
E. the Windows Server 2019 container images hosted in the Azure Container Registry
Correct Answer: CE

With the help of AZ-400 dumps, you can increase your knowledge and experience in your subject without spending too much time.

Comments are closed.