🔥 40% Off Crucial Exams Memberships — This Week Only

3 days, 11 hours remaining!

Microsoft DevOps Engineer Expert AZ-400 Practice Question

Your team hosts a private GitHub repository that contains a Node.js application with several package.json files located in different subfolders. You are tasked with configuring Dependabot to open pull requests only when an update remediates a known vulnerability. Pull requests for routine version bumps that do not address a security issue must be prevented.

Which configuration in the .github/dependabot.yml file will meet this requirement?

  • Add a single updates block with directory: "/" and add @dependabot ignore version-updates to the dependabot.yml comments.

  • Add an updates block for each folder containing a package.json file and set security-updates-only: true within each block.

  • Add an updates block for each folder containing a package.json file and set open-pull-requests-limit: 0 within each block.

  • Enable 'Dependabot security updates' and disable 'Dependabot version updates' in the repository settings, without creating a dependabot.yml file.

Microsoft DevOps Engineer Expert AZ-400
Develop a security and compliance plan
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot