exam questions

Exam AZ-400 All Questions

View all questions & answers for the AZ-400 exam

Exam AZ-400 topic 4 question 23 discussion

Actual exam question from Microsoft's AZ-400
Question #: 23
Topic #: 4
[All AZ-400 Questions]

You have an Azure DevOps organization named Contoso, an Azure DevOps project named Project1, an Azure subscription named Sub1, and an Azure key vault named vault1.
You need to ensure that you can reference the values of the secrets stored in vault1 in all the pipelines of Project1. The solution must prevent the values from being stored in the pipelines.
What should you do?

  • A. Create a variable group in Project1.
  • B. Add a secure file to Project1.
  • C. Modify the security settings of the pipelines.
  • D. Configure the security policy of Contoso.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
AS007
Highly Voted 4 years, 11 months ago
Correct
upvoted 25 times
...
thijsvb
Highly Voted 4 years, 7 months ago
Anwer is correct, because in a variable group you can link a key vault. Then you can make the group available to everyone. This way you can ensure that every pipeline can use the variables. Better useability then using tasks in every pipeline.
upvoted 15 times
gautamksr
4 years, 4 months ago
correct
upvoted 2 times
...
...
nikolayivanov
Most Recent 3 months, 1 week ago
Selected Answer: A
The correct answer is: A. Create a variable group in Project1 Why other options are incorrect: B. Add a secure file to Project1: Secure files are used to upload files (e.g., certificates) securely to pipelines. This does not apply to referencing Azure Key Vault secrets. C. Modify the security settings of the pipelines: Changing pipeline security settings does not provide the functionality needed to securely reference Key Vault secrets. D. Configure the security policy of Contoso: Configuring a security policy at the organizational level is not required to link Azure Key Vault secrets to pipelines. Security policies are broader and do not directly address this scenario.
upvoted 2 times
...
GPRai
10 months, 1 week ago
Selected Answer: A
Correct
upvoted 1 times
...
ozbonny
1 year, 2 months ago
Selected Answer: A
A. Create a variable group in Project1.
upvoted 1 times
...
vsvaid
1 year, 4 months ago
Selected Answer: A
Agree with A
upvoted 1 times
...
yana_b
1 year, 8 months ago
Selected Answer: A
Correct answer and relevant explanation
upvoted 1 times
...
Mcelona
2 years, 3 months ago
Selected Answer: A
A is the correct answer
upvoted 1 times
...
meoukg
2 years, 5 months ago
I chose A when I sat on this exam, and I passed :)
upvoted 2 times
...
syu31svc
2 years, 8 months ago
Selected Answer: A
Given link supports A as the answer
upvoted 1 times
...
Govcomm
2 years, 9 months ago
Variable group for accessing Azure Key Vault
upvoted 1 times
...
UnknowMan
2 years, 11 months ago
Correct
upvoted 1 times
...
rdemontis
3 years, 1 month ago
Selected Answer: A
Correct answer https://docs.microsoft.com/en-us/azure/devops/pipelines/library/variable-groups?view=azure-devops&tabs=yaml#link-secrets-from-an-azure-key-vault
upvoted 3 times
...
celciuz
3 years, 8 months ago
This question came out too, August 2021
upvoted 3 times
...
francis6170
3 years, 10 months ago
Got this in the AZ-400 exam (June 2021).
upvoted 3 times
...
Kalaismile06
3 years, 11 months ago
Question already repeated.
upvoted 1 times
MacawLord
3 years, 9 months ago
It's quite similar to Question #23 in this same question set, only differences are this one has an Azure subscription and needs to prevent the values from being stored in pipelines
upvoted 2 times
...
...
Yogothegreat
4 years, 11 months ago
Using Variable Group is a right answer but Secrets stored in vault1 in all the pipelines of Project1 can be directly accessed if we add a KeyVault Task in the pipeline, whats the purpose of reading it into Variable group, for sharing it across many stages in pipeline ? can someone throw more light
upvoted 6 times
hart232
4 years, 11 months ago
Looks to be a near appropriate answer compared to the available options.
upvoted 1 times
...
Doenoe
4 years, 10 months ago
I think it's the better choice from a security perspective. You would populate the variable group from KeyVault periodically and only when needed, instead of querying the 'external' KeyVault for secrets everytime the pipeline runs.
upvoted 6 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago