Microsoft DevOps Engineer Expert AZ-400 Practice Question
You are designing an Azure Pipelines YAML pipeline that will run only on Microsoft-hosted agents. The pipeline must deploy Bicep templates to an Azure subscription while meeting the following requirements:
Do not store any long-lived client secrets or certificates in Azure DevOps.
Rely on short-lived tokens issued by Azure AD.
Allow scoping permissions to a single resource group. Which authentication approach should you implement in the pipeline's service connection to meet the requirements?
Store an App Service publish profile as a secure file and reference it during the deployment stage.
Create an Azure Resource Manager service connection that uses a service principal secured by a client secret stored in a variable group.
Enable a system-assigned managed identity on the Microsoft-hosted agent and grant it the required Azure RBAC role.
Create an Azure Resource Manager service connection that uses Workload Identity Federation (OIDC) with a federated credential on an Azure AD application.
Workload Identity Federation lets Azure DevOps request a short-lived Azure AD access token for a specific app registration by presenting the pipeline's OpenID Connect (OIDC) token. No client secret or certificate is stored in Azure DevOps, and the service principal created for the registration can be assigned granular roles (for example, at a single resource-group scope). Microsoft-hosted agents cannot use managed identity, a stored publish profile exposes long-lived secrets, and a classic service principal with a client secret still requires secret storage and rotation.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Workload Identity Federation in Azure?
Open an interactive chat with Bash
How does OpenID Connect (OIDC) work in Azure Pipelines?
Open an interactive chat with Bash
Why can’t Microsoft-hosted agents use managed identities for authentication?
Open an interactive chat with Bash
Microsoft DevOps Engineer Expert AZ-400
Develop a security and compliance plan
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .