Microsoft DevOps Engineer Expert AZ-400 Practice Question
Your company hosts all application source code in Azure DevOps Repos. Compliance rules require that every repository is continuously scanned for the following:
accidental commits of credentials or tokens
vulnerable or non-permissive open-source dependencies
security defects in application code across multiple languages You must minimize tool sprawl and management overhead while meeting all requirements inside Azure DevOps. Which strategy should you adopt?
Integrate Azure Key Vault with a Fortify static analysis task in every pipeline to identify hard-coded secrets and code vulnerabilities.
Apply Azure Policy for Azure DevOps and execute SonarQube analysis in a build stage to cover security and compliance needs.
Enable GitHub Advanced Security for Azure DevOps and configure CodeQL analysis, secret scanning, and Dependabot alerts for each repository.
Add Microsoft Defender for Cloud DevOps Security and rely on its default policy assessments for all repositories.
GitHub Advanced Security for Azure DevOps delivers three integrated scanners: secret scanning to detect committed credentials, Dependabot alerts (with licensing information) to surface vulnerable or restrictive dependencies, and CodeQL code scanning for multi-language security analysis. Enabling the extension and turning on the three features at the repository or organization level satisfies every stated requirement without adding separate tools. Microsoft Defender for Cloud DevOps Security focuses on infrastructure posture and does not include code or secret scanning. Azure Key Vault and Fortify do not address dependency or license issues. Azure Policy and SonarQube do not natively scan for secrets or dependency licenses, and would still require additional tools, so they fail to meet the consolidated requirement.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is GitHub Advanced Security for Azure DevOps?
Open an interactive chat with Bash
What is CodeQL and how does it improve security?
Open an interactive chat with Bash
How does Dependabot help with open-source dependency security?
Open an interactive chat with Bash
Microsoft DevOps Engineer Expert AZ-400
Develop a security and compliance plan
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .