Courseiva
← Back to Microsoft Azure DevOps Engineer Expert AZ-400 questions

Scenario-based practice

Refer to the Exhibit Practice Questions

Practise Microsoft Azure DevOps Engineer Expert AZ-400 practice questions — original exam-style scenarios covering every exam domain, with detailed explanations, wrong-answer analysis, and common exam traps.

15
scenario questions
AZ-400
exam code
Microsoft
vendor

Scenario guide

How to approach refer to the exhibit practice questions

Practise exhibit-style questions that ask you to read a topology, table, command output or diagram before choosing the best answer.

Quick answer

Exhibit-style questions test whether you can read a topology, command output, diagram or table before choosing the best answer.

How to extract the relevant detail from an exhibit.

How topology, command output or routing information affects the answer.

How to avoid answering from memory before reading the evidence.

How to map the exhibit back to the exam objective.

Related practice questions

Related AZ-400 topic practice pages

Scenario questions usually connect to one or more exam topics. Use these links to review the underlying concepts behind the scenario.

Practice set

Practice scenarios

Question 1hardmultiple choice
Full question →

Refer to the exhibit. The JSON above shows a branch policy configuration for the main branch in Azure Repos. A developer pushes a third commit to an existing pull request after two reviewers have already approved. What happens?

Exhibit

{
  "policies": {
    "required_reviewers": 2,
    "dismiss_stale_reviews": true,
    "require_code_owner_review": true,
    "require_last_push_approval": true,
    "allowed_merge_types": ["squash", "rebase"]
  }
}
Question 2hardmultiple choice
Full question →

Refer to the exhibit. A build pipeline uses this trigger configuration. A developer pushes a commit to the 'main' branch that modifies files in '/src/app/' and '/src/tests/'. How many builds will be triggered?

Exhibit

{
  "triggers": [
    {
      "branchFilters": ["main", "develop"],
      "paths": {
        "include": ["/src/*"],
        "exclude": ["/src/tests/*"]
      },
      "batchChanges": true,
      "maxConcurrentBuildsPerBranch": 1,
      "triggerType": "continuousIntegration"
    }
  ]
}
Question 3mediummultiple choice
Full question →

Refer to the exhibit. A release is created with the above command. The Dev environment starts deploying, but the Prod environment does not. Which is the most likely reason?

Network Topology
az pipelines release createdefinition-id 5description "Release v1.0"artifacts '{"build":{"buildId":123}}'output json"id": 45,"status": "inProgress","createdOn": "2025-03-03T12:00:00Z","modifiedBy": null,"releaseDefinition": {"id": 5,"name": "ReleasePipeline"},"environments": ["name": "Dev","preDeployApprovals": [],"deploySteps": []"name": "Prod","status": "notStarted",
Question 4hardmultiple choice
Full question →

Refer to the exhibit. The workflow runs successfully but the deployment fails because the Azure CLI is not authenticated. What should you add to the workflow to authenticate?

Network Topology
az webapp deployresource-group myRGname myAppsrc-path ./app.zipRefer to the exhibit.```yaml# .github/workflows/deploy.ymlname: Deployon:push:branches:- mainjobs:deploy:runs-on: ubuntu-latestenvironment: productionsteps:- uses: actions/checkout@v2- name: Deploy to Azurerun: |```
Question 5easymultiple choice
Full question →

The exhibit shows an Azure CLI command to run a pipeline. What does this command do?

Network Topology
$ az pipelines runname "MyPipeline"branch mainvariables myVar="value1"Refer to the exhibit.```bash```
Question 6mediummultiple choice
Full question →

Refer to the exhibit. An Azure DevOps pipeline has the YAML configuration shown. A developer creates a pull request from a feature branch to the develop branch. What will happen?

Exhibit

Refer to the exhibit.

```yaml
# azure-pipelines.yml
trigger:
  branches:
    include:
    - main
    - develop
pr:
  branches:
    include:
    - main

pool:
  vmImage: 'ubuntu-latest'

steps:
- script: echo "Building..."
```
Question 7hardmultiple choice
Full question →

Refer to the exhibit. A developer runs 'git log --oneline --graph --decorate' and sees the output. Which Git workflow does this history most closely represent?

Network Topology
$ git logonelinegraphdecorateRefer to the exhibit.```|/* m2n3o4p Initial commit
Question 8mediummultiple choice
Full question →

Refer to the exhibit. The pipeline YAML includes an Azure CLI script that sets an app setting on a Web App. The pipeline fails with an authentication error. What is the most likely cause?

Network Topology
resource-group rg-contosoname app-contososettings DEPLOYMENT_SLOT=productionRefer to the exhibit.```yaml# Azure CLI scriptecho "Setting environment variables"pipeline:- job: Deploypool:vmImage: 'ubuntu-latest'steps:```
Question 9mediummultiple choice
Full question →

Refer to the exhibit. You have a branch policy JSON for Azure Repos. Which statement about this policy is correct?

Exhibit

{"isDisabled":false,"isLocked":false,"isFrozen":false,"branch":"refs/heads/main","settings":{"scope":[{"refName":"refs/heads/main","matchKind":"Exact","repositoryId":"e6d5f8a1-..."}],"isBlocking":true,"isDeleted":false,"isEnabled":true,"isCommentRequired":true,"isResetOnSourcePush":false,"allowDeletions":false,"allowForcePush":false,"blockLastPusherReview":true,"requireApprovalCount":2,"requireMandatoryReviewers":true,"requireNoMergeConflict":true,"requireSquashMerge":false,"requireTransitionToApproved":true,"requiredReviewerIds":["a1b2c3d4-..."],"buildDefinitionId":1234,"queueOnSourceUpdateOnly":false,"manualQueueOnly":false,"triggeredBuilds":[],"automaticallyLinkedWorkItems":false,"displayName":"Main branch policy"}}
Question 10hardmultiple choice
Full question →

Refer to the exhibit. You run a KQL query in Microsoft Sentinel to audit Azure Container Registry login failures. The result shows 15 failed push attempts to the 'contoso/webapp' repository and 3 failed pull attempts to 'contoso/api'. What is the most likely security implication?

Exhibit

{
  "query": "ContainerRegistryLoginEvents\n| where TimeGenerated > ago(7d)\n| where ResultType != 'Success'\n| summarize FailureCount = count() by Repository, Action",
  "result": [
    {"Repository": "contoso/webapp", "Action": "push", "FailureCount": 15},
    {"Repository": "contoso/api", "Action": "pull", "FailureCount": 3}
  ]
}
Question 11mediummultiple choice
Full question →

Refer to the exhibit. You are deploying this Bicep file using Azure Pipelines. The 'environment' parameter should be set to 'dev', 'qa', or 'prod' based on the release stage. How should you pass the parameter value?

Exhibit

Refer to the exhibit.
```bicep
resource appService 'Microsoft.Web/sites@2022-09-01' = {
  name: 'myapp-${environment}'  
  location: resourceGroup().location
  properties: {
    serverFarmId: appServicePlan.id
    siteConfig: {
      appSettings: [
        {
          name: 'APPINSIGHTS_INSTRUMENTATIONKEY'
          value: appInsights.properties.InstrumentationKey
        }
      ]
    }
  }
}
```
Question 12hardmultiple choice
Full question →

You have the YAML pipeline shown in the exhibit. What will be the output of the script in the Deploy stage?

Exhibit

Refer to the exhibit.
```yaml
# azure-pipelines.yml
variables:
  - name: environment
    value: 'dev'
stages:
- stage: Build
  jobs:
  - job: BuildJob
    steps:
    - script: echo "Building for $(environment)"
- stage: Deploy
  dependsOn: Build
  condition: succeeded()
  variables:
    environment: 'prod'
  jobs:
  - job: DeployJob
    steps:
    - script: echo "Deploying to $(environment)"
```
Question 13mediummultiple choice
Full question →

Refer to the exhibit. You have an Azure Pipelines YAML file for a .NET Core application. The pipeline is triggered on changes to the main branch, but only for files under src/. After a push to main that modifies a file in src/, the pipeline does not start. What is the most likely reason?

Network Topology
"arguments": "configuration $(buildConfiguration)"Refer to the exhibit.```json"triggers": ["branch": "main","paths": {"include": ["src/*"]],"variables": {"buildConfiguration": "Release","majorVersion": "1"},"stages": ["stage": "Build","jobs": ["job": "BuildJob","steps": ["task": "DotNetCoreCLI@2","inputs": {"command": "build",```
Question 14easymultiple choice
Full question →

You run the Azure CLI command shown in the exhibit. What is the output?

Network Topology
$ az vm listquery "[?location=='eastus'].{Name:nameoutput tableRefer to the exhibit.```Name ResourceGroupvm1 rg-prodvm2 rg-dev
Question 15hardmultiple choice
Full question →

An Azure Policy is defined as shown in the exhibit. You attempt to create a storage account with HTTPS traffic only set to false. What will happen?

Exhibit

Refer to the exhibit.

```
{
  "properties": {
    "policyRule": {
      "if": {
        "allOf": [
          {
            "field": "type",
            "equals": "Microsoft.Storage/storageAccounts"
          },
          {
            "field": "Microsoft.Storage/storageAccounts/supportsHttpsTrafficOnly",
            "equals": "false"
          }
        ]
      },
      "then": {
        "effect": "deny"
      }
    }
  }
}
```

These AZ-400 practice questions are part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style AZ-400 questions with detailed explanations, topic-based practice, mock exams, readiness tracking, and study analytics.