Courseiva

Combining App Service Settings, Variable Groups, and Token Replacement

Your team deploys a web application to Azure App Service using Azure Pipelines. The application requires a configuration file that contains connection strings and app settings. You need to ensure that the configuration is environment-specific and that sensitive values are not exposed in the pipeline logs. The configuration file is stored in a Git repository with different branches for each environment. You also need to support local development with the same configuration approach. Which strategy should you use?

Quick Answer

Splitting configuration by sensitivity is the right approach: non-secret, environment-specific settings live in Azure App Service configuration, secrets go into Azure Pipelines variable groups, and token replacement swaps placeholders in the config file at deployment time — keeping secrets out of the repo and logs while still supporting the same pattern for local development.

⚠ Common exam trap

AZ-400 often tests the misconception that storing secrets in config files or pipeline variables without proper masking is acceptable, or that a single config file with overrides is sufficient; candidates must recognize the need for secure secret storage and environment-specific configuration.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Store environment-specific settings in Azure App Service configuration, and use variable groups in Azure Pipelines for secrets. Use token replacement in the config file during deployment.

The correct strategy is to store environment-specific settings in Azure App Service configuration (which can be set per slot/environment) and use Azure Pipelines variable groups for secrets, ensuring they are not exposed in logs. Token replacement in the config file during deployment allows the same config file to be used across environments while injecting environment-specific values. This supports local development because developers can use local settings or user secrets without committing sensitive data.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Store all settings, including secrets, in the config file in each branch. Use a script to replace tokens.

    Why it's wrong here

    Committing secrets to a branch exposes them in Git history and in pipeline logs during token replacement, breaching the sensitivity requirement. Token replacement suits non-secret, per-environment values. It is tempting because branch-per-environment naturally isolates configuration, but secrets belong in Azure Key Vault linked to variable groups.

  • ✗

    Use Azure App Service slots with sticky settings and store all settings in a single config file committed to the repository.

    Why it's wrong here

    Sticky slot settings swap with the slot rather than the app, and a single committed config file cannot vary per environment while keeping secrets out of the repository. Slots suit warm swap and staged rollout, not environment-specific secret storage. Secrets require Azure Key Vault references in App Service settings.

  • ✓

    Store environment-specific settings in Azure App Service configuration, and use variable groups in Azure Pipelines for secrets. Use token replacement in the config file during deployment.

    Why this is correct

    Token replacement keeps the same config file across branches while substituting environment-specific values at deploy time, and variable groups hold secrets so they are masked in logs. App Service configuration supplies runtime settings, satisfying environment-specificity, secret protection and local development parity.

  • ✗

    Use the same config file for all environments and override settings using pipeline variables based on branch name.

    Why it's wrong here

    A shared config file cannot hold environment-specific values, and pipeline variables marked as secrets are still masked only in logs, not stored securely for local development. Variable overrides suit non-secret toggles. The requirement for identical local and deployed configuration points to Azure App Configuration with Key Vault references.

About these practice questions

One of 696 original AZ-400 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on AZ-400

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Your team is using Azure Pipelines to deploy a web application to Azure App Service. The application uses a configuration file (appsettings.json) that contains environment-specific settings. You need to manage these settings across development, staging, and production environments without exposing secrets in the source code. The pipeline should automatically replace the settings during deployment. What should you configure?

medium
  • ✓ A.Use the 'File Transform' task in the release pipeline to replace tokens in the configuration file with variables defined in pipeline variable groups.
  • B.Create separate build configurations for each environment and use the 'Transform Web.config' task.
  • C.Use the 'Azure App Service Deploy' task with the 'Use Web Deploy' option and configure parameterization.
  • D.Set environment variables in the Azure App Service and read them in the application code.

Why A: The File Transform task in Azure Pipelines can perform token replacement in configuration files like appsettings.json using variables defined in pipeline variable groups. This allows environment-specific settings to be injected during deployment without hardcoding secrets in source control. Variable groups can be linked to Azure Key Vault for secure secret management.

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This AZ-400 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-400 exam.