Microsoft Certified: DevOps Engineer Expert practice questions
209 free questions with answers and explanations.
- 151.A software development company is using Azure DevOps for its CI/CD pipelines. They have implemented a security gate in their release pipeline that requires manual approval from a security team lead before deploying to production. This approval process must be auditable and clearly recorded within Azure DevOps. Which Azure DevOps feature should the team configure to implement this security gate?Develop a security and compliance plan
- 152.A DevOps team is implementing a security monitoring strategy for their Azure environment. They need a solution that can collect security logs from various Azure services (e.g., Azure AD, Azure Firewall, VMs), detect sophisticated threats using built-in machine learning, and provide automated incident response capabilities (SOAR). Which Azure service is designed to fulfill these comprehensive security requirements?Develop a security and compliance plan
- 153.A DevOps team is deploying an Azure Kubernetes Service (AKS) cluster for a critical production application. They need to ensure that all container images deployed to the cluster originate from trusted sources and have been scanned for vulnerabilities. Which two Azure services should they integrate to enforce this policy?Develop a security and compliance plan
- 154.A multinational corporation needs to ensure that all Azure resources deployed within specific subscriptions are located only in approved geographic regions (e.g., 'East US 2', 'West Europe'). Any attempt to deploy resources outside these approved regions should be prevented. Which Azure service should the DevOps team use to enforce this geographical restriction?Develop a security and compliance plan
- 155.A healthcare organization is migrating its on-premises applications to Azure. They need to ensure that all data stored in Azure Storage Accounts (Blob, File, Queue, Table) is encrypted at rest using customer-managed keys (CMK) from Azure Key Vault. This is a strict regulatory requirement. Which Azure Storage encryption feature should be configured to meet this specific requirement?Develop a security and compliance plan
- 156.A company is migrating its on-premises applications to Azure. They have a strict compliance requirement to audit all administrative actions performed on Azure resources, including who performed the action, when, and what changes were made. Which Azure service should be used to meet this auditing requirement?Develop a security and compliance plan
- 157.A global software company is building a multi-tenant SaaS application on Azure. They need to ensure strict isolation between tenants' data and resources. Furthermore, they must comply with data residency requirements, meaning customer data for specific regions must remain within those regions. Which Azure architectural pattern and service combination is most suitable for achieving both tenant isolation and data residency?Develop a security and compliance plan
- 158.A DevOps team is responsible for managing multiple Azure subscriptions, each belonging to a different business unit. Each business unit has specific cost management and resource tagging requirements. The team needs a hierarchical structure to apply these governance policies consistently across all subscriptions and to delegate administrative responsibilities effectively. Which Azure feature should they implement?Develop a security and compliance plan
- 159.A company is developing a new serverless application using Azure Functions. They need to ensure that the functions can securely access resources in a private virtual network (VNet) without exposing the VNet to the public internet. Additionally, all outbound traffic from the functions must be routed through a centralized firewall for inspection and control. Which Azure networking capabilities should be configured for the Azure Functions app?Develop a security and compliance plan
- 160.A highly regulated organization needs to ensure that all Azure resources are provisioned according to strict internal security baselines and external compliance standards (e.g., ISO 27001, HIPAA). They want to prevent non-compliant resources from being deployed and automatically remediate any deviations from the baseline. Which Azure service should be used to achieve this proactive compliance enforcement?Develop a security and compliance plan
- 161.A global enterprise is migrating its legacy applications to Azure. They need to ensure that all Azure resources deployed within specific subscriptions are tagged with 'CostCenter' and 'Environment' tags. Furthermore, if these tags are missing or have non-compliant values, the resources should automatically be updated to include the correct tags. Which Azure service should the DevOps team use to implement this tagging strategy?Develop a security and compliance plan
- 162.A financial services organization is implementing a new Azure environment. Regulatory compliance requires that all Azure Virtual Machines (VMs) must have a specific set of security extensions installed and configured upon creation, and non-compliant VMs must be automatically remediated or flagged for review. Which Azure service should the DevOps team leverage to enforce this policy across all subscriptions and resource groups?Develop a security and compliance plan
- 163.A DevOps team is deploying a new web application to Azure App Service. The application will store sensitive customer data in an Azure SQL Database. The security team mandates that all data in transit between the App Service and the SQL Database must be encrypted using a robust, industry-standard protocol. Which of the following configurations should the DevOps team prioritize to meet this requirement?Develop a security and compliance plan
- 164.A multinational corporation needs to ensure that all Azure resources deployed within specific subscriptions adhere to data residency requirements for different geographical regions. For example, resources in the 'Europe' subscription must only be deployed to 'West Europe' or 'North Europe' regions, while resources in the 'US' subscription must only be deployed to 'East US' or 'West US 2'. How can a DevOps engineer enforce these region-specific compliance rules across their Azure environment?Develop a security and compliance plan
- 165.A DevOps team is implementing a security monitoring strategy for their Azure environment. They need to centralize security alerts, incidents, and audit logs from various Azure services (e.g., Azure AD, Azure Firewall, Azure Key Vault) for threat detection, investigation, and automated response. Which Azure service is designed for this purpose?Develop a security and compliance plan
- 166.A financial services company is developing an application that processes credit card information. They are required by PCI DSS compliance to regularly scan their application code for security vulnerabilities. Which type of tool should be integrated into their CI/CD pipeline to automatically identify security flaws in the source code before deployment?Develop a security and compliance plan
- 167.A development team is implementing a new microservices-based application on Azure. They need to ensure that all communication between microservices is encrypted in transit and that each microservice can verify the identity of the other services it communicates with. Which Azure security feature should they prioritize for this requirement?Develop a security and compliance plan
- 168.A company is developing a highly sensitive application that processes personal health information (PHI). They are using Azure App Services and Azure Key Vault to store secrets and certificates. Current security requirements state that all access to Azure Key Vault must originate from a private IP address within a specific Azure Virtual Network (VNet) and must not traverse the public internet. Which Key Vault networking feature should be configured to meet this requirement?Develop a security and compliance plan
- 169.A DevOps team is deploying a new web application to Azure App Service. The application will store sensitive user data in an Azure SQL Database. The security requirement states that all communication between the web application and the database must be encrypted in transit using FIPS 140-2 validated cryptography. Which of the following is the MOST appropriate method to ensure this requirement is met?Develop a security and compliance plan
- 170.A DevOps team is developing a new serverless application using Azure Functions. The application needs to access sensitive data stored in an Azure Key Vault and a backend API hosted in an Azure App Service. Both the Key Vault and the App Service are configured to only allow access from specific Virtual Networks (VNets). How should the DevOps team configure the Azure Function to securely access these resources while adhering to the VNet access restrictions?Develop a security and compliance plan
- 171.A global software company maintains several Azure subscriptions for different development, test, and production environments. They need to ensure that all virtual networks (VNets) created across these subscriptions are peered with a central hub VNet in the production subscription for secure, internal network routing. Furthermore, this peering must be established automatically whenever a new VNet is created. Which Azure service combination provides the most efficient and compliant solution?Develop a security and compliance plan
- 172.A DevOps team is deploying sensitive APIs to Azure App Service. They need to restrict access to these APIs so that only other authorized Azure services (e.g., Azure Functions, Logic Apps) within their virtual network can call them. External internet access must be blocked. Which networking feature should be configured on the Azure App Service to achieve this?Develop a security and compliance plan
- 173.A company is required to implement a 'least privilege' security model for their Azure environment. They want to ensure that developers only have permissions to deploy resources within specific resource groups for their projects, and only to specific resource types (e.g., Web Apps, Azure SQL Database). They should NOT be able to create Virtual Networks or modify subscription-level settings. Which Azure service is best suited to define and enforce these granular permissions?Develop a security and compliance plan
- 174.A global software company maintains numerous Azure DevOps organizations, projects, and release pipelines. They need to standardize their release process across all projects, ensuring consistency in deployment steps, approval workflows, and gate configurations. Maintaining individual pipeline definitions for each project is becoming unmanageable. Which Azure DevOps feature should they use to enforce this standardization efficiently?Design and implement pipelines
- 175.A DevOps team is managing a complex application deployed to an Azure Kubernetes Service (AKS) cluster. They need to ensure that application configurations, which include sensitive API keys and connection strings, are securely injected into pods at runtime without hardcoding them in container images or YAML manifests. These configurations also need to be easily updated and managed centrally. What is the most secure and efficient method to achieve this in AKS?Design and implement pipelines
- 176.A DevOps team is migrating an existing application to a microservices architecture on Azure. They need to provision and manage the infrastructure for each microservice, including compute, networking, and storage, in a repeatable and consistent manner. The team wants to use a tool that supports declarative configuration, allows for state management, and can target multiple cloud providers, although their current focus is Azure. Which Infrastructure as Code (IaC) tool is the most appropriate choice?Design and implement pipelines
- 177.A company is migrating its existing data warehouse solution to Azure. They need to provision and manage the entire Azure infrastructure, including Azure Synapse Analytics workspaces, Azure Data Lake Storage Gen2, and various networking components, using Infrastructure as Code (IaC). The team plans to use a single, consistent tool that can manage resources across different cloud providers in the future, if needed. Which IaC tool is the most appropriate choice for this scenario?Design and implement pipelines
- 178.A DevOps team is developing a new microservices-based application using Azure Kubernetes Service (AKS). They need to implement a robust disaster recovery strategy for their Azure Pipelines YAML definitions. The primary goal is to ensure that all pipeline definitions are versioned, easily recoverable to a previous state, and can be restored quickly in case of accidental deletion or corruption, without relying solely on Azure DevOps' internal retention policies. Which approach should the team take?Design and implement pipelines
- 179.A DevOps team is managing a complex application deployed to an Azure Kubernetes Service (AKS) cluster. The application consists of multiple microservices, each with its own Docker image. They need to ensure that external HTTP/HTTPS traffic can be routed to the correct microservice based on the URL path or hostname. Additionally, they require SSL termination and potentially load balancing for incoming requests. Which Kubernetes resource is best suited to manage these requirements?Design and implement pipelines
- 180.A DevOps team is implementing a release pipeline for a critical microservice. The team wants to ensure that before any new version is deployed to production, a series of automated health checks and performance tests are successfully completed on a staging environment. Additionally, if the deployment fails, the previous stable version must be automatically restored. Which capability of Azure Pipelines should the team leverage to meet these requirements?Design and implement pipelines
- 181.A DevOps team is developing a microservices-based application. Each microservice has its own Git repository and CI pipeline. The team wants to deploy updates to individual microservices independently without affecting other services or requiring a full application redeployment. They also need to ensure that the deployment infrastructure for each microservice is provisioned and managed as code. Which deployment strategy and infrastructure approach should they combine?Design and implement pipelines
- 182.A DevOps team is responsible for managing several Azure Kubernetes Service (AKS) clusters across different environments (Dev, Test, Prod). They need a secure and auditable way for Azure Pipelines to connect to these AKS clusters to deploy applications. The connection must not expose sensitive credentials directly in the pipeline definition and should leverage Azure Active Directory (AAD) authentication for identity management. Which type of Azure DevOps service connection should be used?Design and implement pipelines
- 183.A DevOps team is implementing a complex deployment process for a new application that consists of multiple microservices. Each microservice needs to be deployed to a separate Kubernetes namespace within an AKS cluster. The deployment pipeline must ensure that dependent microservices are deployed in the correct order and that, after each microservice deployment, a set of integration tests specific to that microservice are executed. Which Azure Pipelines feature is best suited to orchestrate this ordered, conditional, and test-driven deployment?Design and implement pipelines
- 184.A DevOps team is implementing a hybrid deployment infrastructure for a legacy application that requires specific on-premises hardware and software. They need to integrate the CI/CD pipeline in Azure DevOps with this on-premises environment to build and deploy the application. The on-premises environment is isolated and cannot be directly exposed to the internet. Which component is required to enable Azure Pipelines to interact with this isolated on-premises environment?Design and implement pipelines
- 185.A company is implementing a new release strategy for a business-critical application that relies on an Azure SQL Database. The application's release pipeline in Azure DevOps needs to include a step to automatically update the database schema as part of the deployment process. This update must be idempotent, version-controlled, and capable of handling both new deployments and upgrades. Which tool or approach is best suited for this requirement?Design and implement pipelines
- 186.A DevOps team is setting up a release pipeline for a new application that will be deployed to Azure App Service. The application needs to have minimal downtime during deployments, and the team wants to easily validate the new version in a production-like environment before swapping it to active production traffic. Additionally, they need to be able to quickly revert to the previous version if any issues are found after the swap. Which Azure App Service feature should they leverage?Design and implement pipelines
- 187.A DevOps team is managing a critical application deployed to Azure Kubernetes Service (AKS). They need to ensure that all deployments to production follow a strict approval process and that automated checks are performed before the deployment proceeds. Specifically, they need to ensure that a senior engineer approves the deployment and that an external security scan completes successfully. Which feature in Azure DevOps release pipelines should be used to enforce these controls?Design and implement pipelines
- 188.A DevOps team is developing a new application that will be deployed across multiple Azure regions for high availability and disaster recovery. They need a deployment strategy that allows them to roll out updates to one region at a time, validate the deployment in that region, and only then proceed to the next region. If an issue is detected, the rollout should halt, and the problematic region should be rolled back without affecting other regions. Which deployment strategy best fits this scenario?Design and implement pipelines
- 189.A large enterprise uses Azure DevOps to manage hundreds of release pipelines across multiple projects. Many of these pipelines share common deployment steps, such as deploying to an Azure Web App or creating a resource group. The DevOps team wants to standardize these common steps to ensure consistency, reduce duplication, and simplify maintenance. Changes to these common steps should propagate across all pipelines that use them. Which Azure DevOps feature should they implement?Design and implement pipelines
- 190.A DevOps team is setting up a release pipeline for an application deployed to multiple Azure App Service instances across different regions. They need to ensure that the deployment to each region occurs sequentially, with a delay between regions to allow for monitoring and validation. Additionally, after each regional deployment, a manual approval from the regional operations lead is required before proceeding to the next region. Which combination of Azure Pipelines features should be used to implement this controlled rollout?Design and implement pipelines
- 191.A company uses Azure DevOps for its CI/CD pipelines. They have a complex application that requires specific environmental variables and configuration settings for each deployment stage (Dev, Test, Prod). These settings change frequently and contain sensitive information that should not be hardcoded in the pipeline YAML or stored directly in variable groups. Which Azure DevOps feature should the team use to manage these settings securely?Design and implement pipelines
- 192.A DevOps team is developing a microservices-based application using Azure Kubernetes Service (AKS). Each microservice has its own Git repository and a dedicated Azure Pipeline for CI/CD. The team needs to ensure that when a change is committed to the main branch of any microservice, its corresponding pipeline automatically triggers, builds the Docker image, and updates the deployment in AKS. Which type of trigger should be configured in each microservice's Azure Pipeline?Design and implement pipelines
- 193.A global e-commerce company uses Azure DevOps to manage its release pipelines for a critical web application. They need to ensure that database migrations are applied correctly and consistently across all environments (staging, production) as part of their deployment process. The migrations should be reversible, and the system must track which schema versions are deployed to each database. Which tool or approach is best suited for this requirement?Design and implement pipelines
- 194.A DevOps team is deploying a new version of an application to an Azure Kubernetes Service (AKS) cluster. They want to expose the application externally via a public IP address and ensure that incoming traffic is securely routed to the correct service within the cluster. Additionally, they need to manage SSL/TLS termination and potentially implement advanced routing rules based on host or path. Which Kubernetes resource should they configure to achieve this?Design and implement pipelines
- 195.A company uses Azure DevOps for its CI/CD pipelines and wants to implement a robust disaster recovery plan for their YAML-based release pipelines. They need to ensure that pipeline definitions, including stages, jobs, and tasks, are backed up and can be restored in case of accidental deletion, corruption, or an Azure DevOps service outage. What is the most effective approach to achieve this goal?Design and implement pipelines
- 196.A DevOps team is responsible for deploying a critical line-of-business application to Azure App Services. The application requires a deployment strategy that minimizes downtime to near zero during updates and provides an easy rollback mechanism in case of issues. The team needs to test the new version with a small subset of users before a full rollout. Which deployment strategy should the team implement?Design and implement pipelines
- 197.A large enterprise is deploying a new version of a critical web application to Azure App Service. The deployment needs to be performed during off-peak hours to minimize user impact, and an approval from the change management board is required before the deployment can proceed. After a successful deployment, an automated smoke test must run, and if it passes, a notification should be sent to the operations team. Which Azure Pipelines features should be configured to meet these requirements?Design and implement pipelines
- 198.A DevOps team is designing a release strategy for a new web application. The application needs to be deployed to an Azure App Service, and updates must be delivered with minimal downtime. The team wants to test new versions in a separate environment that uses the same App Service plan and configuration as the production environment, but without affecting live traffic. Which deployment strategy should the team implement?Design and implement pipelines
- 199.A DevOps team is deploying a new version of a critical web application to Azure App Service. The application must remain highly available during the deployment process, and the team wants to minimize downtime and provide an easy rollback mechanism if issues arise. They decide to use deployment slots. Which of the following is the MOST appropriate deployment strategy to achieve these requirements?Design and implement pipelines
- 200.A DevOps team is developing a new microservices-based application using Azure Kubernetes Service (AKS). Each microservice has its own Git repository, building its own Docker image, and deploying independently. The team wants to automate the CI/CD process for each microservice. They need to configure their Azure Pipelines such that a new build and deployment is automatically triggered ONLY when changes are pushed to the specific Git repository associated with that microservice. Which trigger configuration should they apply to each microservice's pipeline?Design and implement pipelines