Microsoft DevOps Engineer Expert AZ-400 Practice Question
Your company maintains several Azure DevOps pipelines that deploy workloads to different subscriptions. All runtime connection strings are stored as secrets in a single Azure Key Vault. The security team mandates that the service principal used by the build stage must be able to retrieve only the specific secrets referenced in the pipeline code and must not be able to enumerate other secrets in the vault. Which configuration meets the requirement with the principle of least privilege?
Assign the Reader role to the service principal at the vault scope and reference secrets by name in the pipeline.
Switch the vault to Azure RBAC authorization and assign the service principal the Key Vault Secrets User role at the vault scope.
Keep the vault in access-policy mode and grant the service principal a secrets access policy that includes only the Get operation.
Enable a private endpoint for the vault and restrict inbound IP ranges to the Azure DevOps agent pool.
Key Vault access policies let you assign individual data-plane operations. Granting a service principal the Get permission on secrets provides the ability to read a secret when its name is already known, while withholding the List permission prevents the identity from enumerating all secrets in the vault. Azure RBAC built-in roles such as Key Vault Secrets User include both Get and List actions, network rules do not control data-plane operations, and assigning Reader at the vault scope gives no secret access at all. Therefore, an access policy limited to Secret Get is the correct choice.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Azure Key Vault?
Open an interactive chat with Bash
What is the Principle of Least Privilege?
Open an interactive chat with Bash
What is the difference between Azure Key Vault Access Policies and Azure RBAC?
Open an interactive chat with Bash
Microsoft DevOps Engineer Expert AZ-400
Develop a security and compliance plan
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99 $11.99
$11.99/mo
Billed monthly, Cancel any time.
$19.99 after promotion ends
3 Month Pass
$44.99 $26.99
$8.99/mo
One time purchase of $26.99, Does not auto-renew.
$44.99 after promotion ends
Save $18!
MOST POPULAR
Annual Pass
$119.99 $71.99
$5.99/mo
One time purchase of $71.99, Does not auto-renew.
$119.99 after promotion ends
Save $48!
BEST DEAL
Lifetime Pass
$189.99 $113.99
One time purchase, Good for life.
Save $76!
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .