Microsoft Certified: DevOps Engineer Expert practice questions
209 free questions with answers and explanations.
- 201.A DevOps team is responsible for managing several Azure Kubernetes Service (AKS) clusters across different subscriptions. They need to configure Azure Pipelines to deploy applications to these clusters securely. The security policy dictates that service principals should not be used directly for authentication, and instead, a more secure, managed identity-based approach should be employed. Which type of Azure Pipelines service connection, leveraging a modern authentication method, should the team use?Design and implement pipelines
- 202.A global software company maintains numerous Azure DevOps organizations, projects, and release pipelines. They want to standardize their deployment processes across all teams and projects, ensuring consistency, reusability, and maintainability. Specifically, they need to define common deployment steps, environment configurations, and approval workflows once, and then reuse them across many different applications and pipelines. Which Azure Pipelines feature is BEST suited for this requirement?Design and implement pipelines
- 203.A DevOps team is deploying a new version of an application to an Azure Kubernetes Service (AKS) cluster. The application consists of several microservices, and they need to expose some of these microservices to external users via HTTP/HTTPS. The team also requires features like SSL termination, load balancing, and URL-based routing to direct traffic to the correct microservice. Which Kubernetes resource should the team use to achieve this?Design and implement pipelines
- 204.A global e-commerce company uses Azure DevOps to manage its release pipelines for a critical inventory management system. The system relies on a complex SQL database. New releases frequently involve database schema changes that must be applied in a controlled and reversible manner. The DevOps team needs to ensure that schema migrations are automatically executed as part of the release pipeline and are fully trackable. Which tool or approach should the team integrate into their Azure DevOps release pipeline to address these requirements?Design and implement pipelines
- 205.A company is migrating its existing data warehouse solution to Azure. They need to provision and manage a complex infrastructure that includes Azure Synapse Analytics, several Azure Data Lake Storage Gen2 accounts, Azure Data Factory, and virtual networks across multiple Azure subscriptions and resource groups. The team requires a solution that provides declarative infrastructure definition, supports state management, and can be used to manage resources across different cloud providers in the future. Which Infrastructure as Code (IaC) tool is the MOST suitable for this scenario?Design and implement pipelines
- 206.A DevOps team is implementing a release pipeline for a critical microservice. The team wants to ensure that before a new version is deployed to production, it passes a series of automated health checks, performance tests, and security scans on a staging environment. Additionally, if any of these checks fail, the deployment to production should be automatically prevented. Which Azure Pipelines feature should the team use to enforce these conditions?Design and implement pipelines
- 207.A DevOps team is managing a complex application deployed to an Azure Kubernetes Service (AKS) cluster. The application requires access to sensitive secrets like API keys and database connection strings. To enhance security, the team wants to avoid storing these secrets directly in Kubernetes manifests or as environment variables in pods. They need a solution that allows pods to securely retrieve secrets from Azure Key Vault. Which Azure Kubernetes Service feature, combined with Azure Key Vault, should the team implement?Design and implement pipelines
- 208.A DevOps team is adopting an SRE strategy for a critical, high-traffic web application hosted on Azure. They are defining Service Level Objectives (SLOs) and need to ensure that alerts are actionable and directly tied to user experience. The team wants to be notified when the application's performance degrades to a point that it significantly impacts users, but before the SLO is fully breached. Which alerting strategy should the team implement?Implement a Site Reliability Engineering (SRE) strategy
- 209.A global e-commerce company uses Azure DevOps for its CI/CD pipelines. They have multiple development teams working on different microservices, each with its own Azure subscription. The company's security policy mandates that all production deployments must be reviewed and approved by a separate security operations team before being released. This approval process should be integrated directly into the deployment pipeline and prevent any unapproved changes from reaching production. Additionally, the security team needs to be able to manually trigger a rollback or hold a deployment if a critical vulnerability is discovered post-approval but pre-release. Which Azure DevOps feature should the company implement to meet these requirements?Develop a security and compliance plan