Three Practices That Prevent Secret Exposure in Azure Pipelines Logs
Your team uses Azure DevOps and needs to ensure that secrets are not exposed in pipeline logs. Which THREE practices should you implement?
Quick Answer
The ##vso[task.setvariable variable=mySecret;isSecret=true]value logging command is what actually masks a variable's value in Azure Pipelines logs — even if a script accidentally echoes the secret, the output gets replaced with asterisks, which is a direct, built-in safeguard against accidental exposure during a run.
⚠ Common exam trap
It's easy for candidates to confuse log masking with encryption, assuming that enabling 'pipeline log encryption' is a real Azure DevOps feature, when in fact the platform relies on secret variable masking and Azure Key Vault integration for secret management.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use logging commands to mask secrets in scripts
Option A is correct because Azure Pipelines supports the logging command `##vso[task.setsecret]value` (and the older `##vso[task.setvariable variable=name;issecret=true]`) to explicitly register a value with the agent so it is masked as `***` anywhere it appears in pipeline logs. Option C is correct because marking a variable as 'secret' in pipeline variables (via the UI lock icon or `issecret=true` in YAML) causes Azure DevOps to encrypt the value at rest and automatically mask it in logs. Option E is correct because Azure Key Vault stores secrets outside the pipeline definition and, when linked via a variable group or the `AzureKeyVault@2` task, the retrieved values are automatically treated as secrets and masked in logs, while also enforcing access control and rotation. Option B is not a real Azure DevOps feature — pipeline logs are not configured via a 'log encryption' toggle; masking is achieved through secret variables and logging commands. Option D is incorrect because storing secrets in plain YAML variable files commits them to the repository in cleartext, which is exactly the exposure the team must avoid.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Use logging commands to mask secrets in scripts
Why this is correct
Logging commands such as ##vso[task.setsecret] register values with the agent so they are masked in pipeline output. This satisfies the requirement to prevent secrets appearing in logs, since the agent replaces registered values with asterisks.
- ✗
Enable pipeline log encryption
Why it's wrong here
Azure DevOps already encrypts pipeline logs in transit and at rest; no such toggle exists, so it cannot prevent secret exposure. It is tempting as a security-sounding control, yet the actual remedy is secret masking and variable groups.
- ✓
Mark variables as 'secret' in pipeline variables
Why this is correct
Marking variables as secret instructs Azure Pipelines to mask their values in log output, satisfying the requirement that secrets never appear in pipeline logs. The agent replaces secret values with asterisks, preventing accidental disclosure during task execution or debugging output.
- ✗
Store secrets in YAML variable files
Why it's wrong here
YAML variable files are committed to the repository, exposing secrets in plaintext to anyone with read access. They are tempting for versioned configuration, and are correct for non-sensitive values, but secrets belong in Azure Key Vault or secret variables.
- ✓
Use Azure Key Vault to store secrets
Why this is correct
Storing secrets in Azure Key Vault keeps credentials outside pipeline YAML and variable groups, so they are never echoed into logs. Referencing them via Key Vault task or variable group linked to Key Vault satisfies the stem's constraint that secrets must not be exposed in pipeline logs.
Go deeper
Related to this question
Learn chapter
Source Control Strategy Design
Key term
Azure DevOps
Azure DevOps is a Microsoft service that provides development tools for planning, building, testing, and deploying software applications using automated pipelines and collaboration features.
Key term
Variable group
A variable group is a reusable collection of key-value pairs in Azure DevOps that can store configuration settings and secrets, shared across multiple pipelines.
About these practice questions
One of 696 original AZ-400 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on AZ-400
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which TWO actions should be taken to secure secrets in Azure Pipelines? (Choose two.)
medium- ✓ A.Use secret variables with the 'secret' input type to mask them in logs.
- B.Use a variable group without Key Vault integration for easier management.
- C.Store secrets directly in the YAML pipeline file.
- ✓ D.Store secrets in a variable group linked to Azure Key Vault.
- E.Disable CI triggers to reduce exposure.
Why A: Azure Pipelines allows you to mark variables as secret by using the 'secret' input type in the pipeline settings UI or by setting `secret: true` in YAML. This ensures the variable's value is masked with asterisks in all logs and output, preventing accidental exposure during build or release execution. Additionally, storing secrets in a variable group linked to Azure Key Vault provides a secure, centralized way to manage secrets, with access control, versioning, and auditability, making it a best practice for protecting sensitive data.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-400 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-400 exam.