AZ-400 Sample Questions

AZ-400 Sample Questions & Answers

Build and release pipelines, including package management and testing strategy, take up more than half the exam, with the rest on tracing work item flow and metrics, branching and repository strategy, a security and compliance plan, and monitoring instrumentation.

Launch the full AZ-400 simulator →

Showing 10 of 20 free samples.

  1. Question 1Intermediate

    Design and implement a source control strategy · Design and implement branching strategies for the source code

    A team is adopting trunk-based development using GitHub. To maintain code quality and prevent broken builds, they want to enforce that all pull requests targeting the main branch must pass a series of checks before they can be merged. These checks include a successful build, a minimum code coverage percentage, and a security scan. What GitHub feature should be configured on the main branch to enforce these requirements?

    Show answer & explanation

    Correct answer: C

    Branch protection rules are the specific GitHub feature designed to enforce workflows for one or more branches. You can configure rules that require status checks (like builds, tests, and scans from GitHub Actions) to pass before a pull request can be merged into the protected branch. This directly addresses all the stated requirements.

  2. Question 2Advanced

    Implement an instrumentation strategy · Analyze metrics from instrumentation

    A DevOps engineer needs to write a Kusto Query Language (KQL) query in Log Analytics to investigate performance issues. The goal is to find the average request duration for all failed requests (resultCode starts with '5') in the requests table over the last 24 hours, summarized into 1-hour intervals. Which KQL query correctly accomplishes this?

    Show answer & explanation

    Correct answer: B

    This query is correct. where timestamp > ago(24h) filters for the last day. resultCode startswith '5' correctly identifies server-side failures. summarize avg(duration) calculates the average duration. by bin(timestamp, 1h) correctly groups the results into 1-hour time bins.

  3. Question 3Intermediate

    Design and implement build and release pipelines · Design and implement deployments

    A manufacturing company is modernizing its application deployment. The primary goal is to minimize downtime and risk when deploying new versions of their critical inventory management web app, which is hosted on Azure App Service. They want to route a small percentage of live traffic to the new version for a period of time to monitor its performance and stability before rolling it out to all users. Which deployment strategy should they implement?

    Show answer & explanation

    Correct answer: C

    The canary release strategy is specifically designed for routing a small subset of production traffic to a new version. In Azure App Service, this is perfectly implemented using deployment slots. One can deploy the new version to a staging slot and then use the traffic routing feature to direct a specified percentage (e.g., 10%) of traffic to that slot, allowing for monitoring before a full rollout.

  4. Question 4Beginner

    Develop a security and compliance plan · Automate security and compliance scanning

    True or False: When using GitHub Advanced Security, secret scanning is limited to detecting secrets only in the default branch of a repository.

    Show answer & explanation

    Correct answer: B

    False. GitHub Advanced Security's secret scanning scans the entire Git history on all branches in a repository for secrets, not just the default branch. It also scans pull requests as they are created.

  5. Question 5Intermediate

    Design and implement build and release pipelines · Design and implement pipelines

    A DevOps team manages multiple projects, each with its own Azure Pipeline. To ensure consistency and reduce redundant code, they want to create a reusable component that defines a sequence of steps for running integration tests. This component should be easily versioned and shared across different pipelines. Which Azure Pipelines feature is best suited for this purpose?

    Show answer & explanation

    Correct answer: C

    YAML templates are the ideal solution for creating versionable and reusable pipeline components. A template can define a set of steps, jobs, or even entire stages that can be imported into multiple pipelines. Since templates are stored as YAML files in a repository, they can be versioned, managed via pull requests, and shared, providing the highest level of reusability and maintainability.

  6. Question 6Advanced

    Design and implement build and release pipelines · Design and implement deployments

    Case Study:

    A healthcare technology company, HealthData Inc., is migrating its monolithic patient portal application to a microservices architecture on Azure Kubernetes Service (AKS). The company operates under strict regulatory compliance (HIPAA) and must maintain a high degree of security and traceability.

    Current Situation:
    The development team uses GitHub for source code management. The current CI/CD process is manual, slow, and error-prone. There is no automated security scanning, and secrets like database connection strings are stored in configuration files within the repositories. The operations team has limited Kubernetes experience, and developers need a way to test their services in isolated, production-like environments before merging code.

    Requirements:

    1. CI/CD Automation: Implement a fully automated build, test, and deployment pipeline using GitHub Actions.
    2. Security: All container images must be scanned for vulnerabilities. Secrets must be removed from source code and managed securely. A full audit trail of all code changes and deployments is required.
    3. Developer Environments: Provide developers with on-demand, self-service environments for testing pull requests.
    4. Deployment Strategy: Deployments to the production AKS cluster must use a progressive exposure model to minimize risk.

    Which proposed solution best addresses all of HealthData Inc.'s requirements?

    Show answer & explanation

    Correct answer: B

    This solution comprehensively addresses all requirements. GitHub Actions provides CI/CD. GitHub Advanced Security handles automated scanning. Azure Key Vault with workload identity offers the best practice for secret management in AKS. Azure Deployment Environments directly solves the need for on-demand, self-service test environments. A canary release strategy is a form of progressive exposure, meeting the deployment requirement.

  7. Question 7Advanced

    Design and implement build and release pipelines · Design and implement a package management strategy

    A team is designing a package management strategy using Azure Artifacts. They produce several internal NuGet packages that are consumed by different applications. They need to create a feed that provides access to their own packages as well as packages from the official nuget.org repository. New applications should only use packages that have been vetted and approved by a quality assurance team. How should they configure their feeds to meet these requirements?

    Show answer & explanation

    Correct answer: C

    This solution correctly uses the features of Azure Artifacts. Enabling nuget.org as an upstream source allows the feed to serve both internal and public packages. Feed views (@local, @prerelease, @release) allow for a promotion model where packages can be vetted in one view (e.g., @local) and then promoted to another (e.g., a custom '@Approved' view) once they pass QA. Developers then connect only to the '@Approved' view, ensuring they only use vetted packages.

  8. Question 8Intermediate

    Design and implement build and release pipelines · Design and implement pipelines

    A DevOps engineer is optimizing a multi-stage YAML pipeline that builds, tests, and deploys a large application. The build and test stages take a significant amount of time. The engineer observes that several independent jobs within the test stage could run concurrently. What is the most effective way to configure the pipeline to run these test jobs in parallel?

    Show answer & explanation

    Correct answer: B

    By default, jobs defined within the same stage will run in parallel, provided there are enough available agents and the jobs do not have dependsOn clauses that would serialize them. This is the standard and most direct way to achieve parallel job execution within a single stage.

  9. Question 9Beginner

    Design and implement processes and communications · Configure collaboration and communication

    A project requires a wiki to document its architecture, coding standards, and release procedures. The documentation will include complex diagrams to illustrate process flows and system interactions. The team wants to store these diagrams as text within the markdown files so they can be version-controlled and easily updated. Which syntax should the team use within the Azure DevOps wiki to embed these diagrams as code?

    Show answer & explanation

    Correct answer: D

    Azure DevOps wikis and GitHub markdown both support Mermaid syntax for rendering diagrams from text. This allows teams to create and embed flowcharts, sequence diagrams, Gantt charts, and more directly within their documentation, meeting the requirement to have version-controllable, text-based diagrams.

  10. Question 10Intermediate

    Design and implement build and release pipelines · Design and implement infrastructure as code (IaC)

    You are creating a Bicep template to deploy an Azure Web App. You need to ensure that the application setting ASPNETCORE_ENVIRONMENT is set based on an input parameter named environmentType. If environmentType is 'Production', the value should be 'Production'; otherwise, it should be 'Development'. Which Bicep expression should you use to define the value of this application setting?

    Show answer & explanation

    Correct answer: C

    Bicep uses the ternary conditional operator (condition) ? true-value : false-value for inline conditional logic. This expression correctly evaluates the environmentType parameter and returns the appropriate string value for the application setting.

Ready for the real thing?

The full AZ-400 simulator has every exam-style question, timed mode, and instant scoring.

Go to the AZ-400 simulator →