Microsoft DevOps Engineer Expert AZ-400 Practice Question
You are connecting an existing Azure DevOps organization to Microsoft Defender for Cloud. During the setup process for the DevOps security connector, you are redirected to Azure DevOps to authorize an OAuth application. This authorization grants Defender for Cloud the necessary permissions to discover repositories and analyze their security posture. To adhere to the principle of least privilege, which minimum set of permission scopes should be granted for the initial onboarding and scanning?
Code (Read), Graph (Read), and Work Items (Read)
Project & Team (Read), Build (Read), and Release (Read)
When you connect an Azure DevOps organization to Microsoft Defender for Cloud, the process uses an OAuth application that requests a set of permissions. To enable Defender for Cloud to enumerate repositories, map users, and understand the context of code commits, a specific set of read-only permissions is required. According to the functionality, the application needs 'Code (Read)' to access repository content, 'Graph (Read)' to map users and groups, and 'Work Items (Read)' to correlate commits with linked work items. Granting broader permissions, such as write access, or unnecessary scopes like 'Build' or 'Release' for the initial connection would violate the principle of least privilege. Omitting any of the required read scopes would cause the connector to fail in discovering and analyzing all relevant resources.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is OAuth and how does it work in Azure DevOps?
Open an interactive chat with Bash
Why is the principle of least privilege important in security?
Open an interactive chat with Bash
What are 'Code', 'Graph', and 'Work Items' permission scopes in Azure DevOps?
Open an interactive chat with Bash
What does the principle of least privilege mean in the context of Azure DevOps security?
Open an interactive chat with Bash
Why are 'Code (Read)', 'Graph (Read)', and 'Work Items (Read)' the minimum required permissions for connecting Azure DevOps to Defender for Cloud?
Open an interactive chat with Bash
What would happen if broader permissions, like 'Code (Read & Write)' or 'Service Hooks (Manage)', were granted to the OAuth application?
Open an interactive chat with Bash
Microsoft DevOps Engineer Expert AZ-400
Develop a security and compliance plan
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .