Microsoft Certified: DevOps Engineer ExpertDesign and implement source controlMedium

A team is using Azure DevOps for their source control and build pipelines. They have several private NuGet feeds hosted in Azure Artifacts. Their build pipelines need to publish new NuGet packages to these private feeds and consume existing packages. To do this securely without hardcoding credentials, which type of Azure DevOps construct should be configured to allow the build pipeline to interact with Azure Artifacts feeds?

  1. AService connection of type 'Azure DevOps Services'
  2. BRepository permissions
  3. CVariable group with feed URLs
  4. DAgent pool capabilities
Show answer & explanation

Correct answer: A. Service connection of type 'Azure DevOps Services'

A 'Service connection' of type 'Azure DevOps Services' is the correct construct. It allows a pipeline to securely authenticate and interact with other Azure DevOps resources within the same organization, including Azure Artifacts feeds, without exposing credentials.

Why the other options are wrong

  • B. Repository permissions control access to source code, not package feeds.
  • C. Variable groups store values, but they don't provide the secure authentication mechanism required for publishing/consuming from feeds.
  • D. Agent pool capabilities define what software is available on agents, not credentials for interacting with feeds.

Azure DevOps Service Connection

A secure way to connect Azure DevOps pipelines to external and internal services (like Azure Artifacts, Azure subscriptions, GitHub) without exposing sensitive credentials directly in pipeline definitions.

  • Stores credentials securely.
  • Used for authentication to external systems.
  • Different types exist for various services.

Memory trick: Connect services securely with a service connection.

More Design and implement source control questions