Microsoft DevOps Engineer Expert AZ-400 Practice Question

Your Azure DevOps YAML pipeline builds a Linux container image and is required to block any image that contains High or Critical vulnerabilities in its operating-system packages before the image is pushed to Azure Container Registry. You must meet the requirement without adding custom scripts or relying on post-push scanning in Microsoft Defender for Cloud. Which action should you take in the pipeline?

  • Enable Microsoft Defender for Cloud container registry scanning and query its alerts after the push to decide whether to fail the build.

  • Configure GitHub Advanced Security CodeQL analysis to run inside a container during the pipeline.

  • Add the Microsoft Security DevOps task and run it in container scan mode with a severity threshold set to fail the job.

  • Enable Dependabot alerts for the repository so that vulnerability data blocks the container push automatically.

Microsoft DevOps Engineer Expert AZ-400
Develop a security and compliance plan
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot