Microsoft DevOps Engineer Expert AZ-400 Practice Question
Your organization stores its source code in Azure DevOps Repos. You need the build stage of a new multi-language YAML pipeline to automatically scan every commit for secrets, vulnerable open-source dependencies, Infrastructure-as-Code misconfigurations, and other security issues. The solution must use a single task, output SARIF-formatted results, and break the build if any high-severity findings are detected, without requiring you to configure each scanner individually. Which task should you add to the pipeline?
Add an OWASP Dependency Check task to scan third-party libraries.
Add the MicrosoftSecurityDevOps@1 task from the Microsoft Security DevOps extension.
Add a Trivy@0 task to perform container image vulnerability scanning.
Add the CodeQLAnalysis@0 task and configure a CodeQL database for each language.
The MicrosoftSecurityDevOps@1 task, provided by the Microsoft Security DevOps extension, orchestrates multiple analyzers (for example CredScan, ESLint, Bandit, PoliCheck, IaC scanners, and dependency-vulnerability tools) in a single step, emits standardized SARIF output, and allows you to set a fail-threshold for high-severity issues. CodeQLAnalysis@0 only performs static code analysis, while Dependency Check and Trivy each cover a single scope (dependency or container scanning). None of those alternatives meet the requirement to run comprehensive, multi-tool scanning through one task.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the MicrosoftSecurityDevOps@1 task used for?
Open an interactive chat with Bash
What is SARIF, and why is it used in security scanning?
Open an interactive chat with Bash
What are some examples of the analyzers coordinated by MicrosoftSecurityDevOps@1?
Open an interactive chat with Bash
Microsoft DevOps Engineer Expert AZ-400
Develop a security and compliance plan
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .