Microsoft DevOps Engineer Expert AZ-400 Practice Question

Your company stores all code in GitHub Enterprise Cloud and deploys workloads to both Azure and AWS. The security team enforces FedRAMP High rules that prohibit long-lived cloud credentials in CI/CD systems. Instead, pipelines must obtain short-lived tokens issued through OpenID Connect (OIDC) at run time. Pipeline definitions must live in the same repository as the code. You need to recommend a deployment automation solution that meets these requirements with the least additional components or custom tasks. Which solution should you choose?

  • Azure Pipelines classic release pipelines with environment-specific service connections that store the required cloud access keys

  • GitHub Actions on self-hosted runners that use repository secrets to store AWS and Azure access keys

  • Azure Pipelines YAML pipelines with an AWS service connection configured from long-lived access keys and an Azure service-principal secret

  • GitHub Actions with GitHub-hosted runners and federated OIDC credentials to Azure and AWS

Microsoft DevOps Engineer Expert AZ-400
Design and implement build and release pipelines
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot