Courseiva

AZ-400 · topic practice

Design and implement build and release pipelines practice questions

This domain covers Azure Pipelines and GitHub Actions: designing multi-stage YAML pipelines, triggers, approvals and gates, agents and pools, caching, artifact handling, and deployment strategies across Dev/Test/Prod. Questions are scenario-based, asking you to pick tasks, triggers, or approval configurations that meet stated release requirements.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Design and implement build and release pipelines

What the exam tests

What to know about Design and implement build and release pipelines

You must be able to design a multi-stage YAML pipeline or GitHub Actions workflow that deploys sequentially to Dev, Test, and Prod with approvals, correct triggers, caching, and artifacts. The most important thing is matching triggers and approval placement to the stated deployment requirement.

Selecting pipeline tasks such as Cache@2 and PublishBuildArtifacts for dependency and artifact handling

Configuring stage triggers, environments, and manual approval checks in Azure Pipelines

Choosing GitHub Actions triggers like pull_request and on: workflow_dispatch for ARM deployments

Using deployment jobs, runOnce/canary/rolling strategies, and service connections for releases

Why learners struggle

Why Design and implement build and release pipelines questions are commonly missed

DHCP questions are missed when learners overlook the relay agent requirement for cross-subnet assignments, or assume that because a DHCP server exists, a client will always get an address. Routing, relay, scope, and exclusion details all affect the outcome.

  • ·DHCP relay required — clients on a different subnet cannot broadcast to a remote DHCP server without a helper address
  • ·Excluded addresses — addresses in an excluded range are never offered, even if they are in the scope
  • ·Default gateway option — must match the client subnet, not the server's subnet
  • ·APIPA address (169.254.x.x) — indicates DHCP discovery failed, not a server response
  • ·DORA flow — Discovery, Offer, Request, Acknowledgement; missing any step breaks assignment
  • ·Scope exhaustion — a full scope returns no addresses even when the server is reachable

Watch out for

Common Design and implement build and release pipelines exam traps

  • ▸Adding approvals on every stage instead of using environment checks or a single gate, inflating approval count unnecessarily
  • ▸Confusing build triggers with release triggers, or using schedule instead of pull_request for PR validation
  • ▸Assuming caching alone speeds builds without correct cache keys, restore keys, or cache scope across jobs

Practice set

Design and implement build and release pipelines questions

20 questions · select your answer, then reveal the explanation

You are reviewing an Azure Policy definition applied to an Azure DevOps project. The project has a build pipeline that deploys to production. What is the effect of this policy on the build pipeline?

Exhibit

Refer to the exhibit.

```json
{
  "properties": {
    "description": "Policy to require multiple reviewers for critical repos",
    "policyType": "Build",
    "mode": "Validation",
    "initiative": "RequireMinimumReviewers",
    "policyRule": {
      "if": {
        "field": "type",
        "equals": "Microsoft.TeamFoundation/teamProjects"
      },
      "then": {
        "effect": "audit",
        "details": {
          "minimumApproverCount": 2
        }
      }
    }
  }
}
```

Refer to the exhibit. The pipeline is configured as shown. A developer pushes a change to the `main` branch that modifies a file under `src/Controllers/HomeController.cs` and also adds a new file under `docs/readme.md`. Which of the following best describes what happens?

Network Topology
configuration $(buildConfiguration)'arguments: 'configuration $no-build'Refer to the exhibit.```yaml# azure-pipelines.ymltrigger:branches:include:- main- release/*paths:exclude:- docs/*- tests/*pool:vmImage: 'ubuntu-latest'variables:buildConfiguration: 'Release'steps:- task: DotNetCoreCLI@2inputs:command: 'build'projects: '**/*.csproj'displayName: 'Build project'command: 'test'projects: '**/*Tests/*.csproj'displayName: 'Run tests'```

Your organization uses Azure Pipelines for CI/CD. The current pipeline for a .NET Core application builds and runs unit tests, then deploys to a staging environment. The team wants to add a step to run integration tests against the staging environment after deployment, and only if integration tests pass, promote the build to production. The integration tests require a database connection string that is stored as a secret in Azure Key Vault. The pipeline uses a service principal with permissions to read secrets from the Key Vault. You need to modify the pipeline to meet these requirements while ensuring security best practices. Which action should you take?

You have a multi-stage YAML pipeline that deploys to Azure Kubernetes Service (AKS). The pipeline uses a deployment job with a strategy of 'runOnce'. You need to ensure that if the deployment fails, the pipeline automatically redeploys the previous successful version. Which strategy should you use instead?

You are designing a release pipeline that uses Azure App Service deployment slots. The pipeline must perform a swap after deployment to the staging slot. Which three tasks or actions should you include in the pipeline? (Select all that apply.)

You have a YAML pipeline that builds a Docker image and pushes it to Azure Container Registry (ACR). You need to ensure the pipeline uses the latest version of Docker and that the build is cached for faster subsequent runs. Which two tasks should you include? (Choose two.)

You are configuring a YAML pipeline that deploys to multiple environments. The pipeline should automatically trigger when changes are pushed to the main branch, but only if the build artifact changes. Which trigger configuration should you use?

Which two actions can you use to validate that a deployment to a staging environment is successful before promoting to production? (Choose two.)

You are designing a pipeline that must run tasks in a container. The container needs access to Azure resources using a managed identity. Which two configurations are required? (Choose two.)

Match each Azure DevOps concept to its correct description.

You have a multi-stage YAML pipeline that deploys to a Linux-based Azure App Service. The pipeline uses a 'Deploy to Azure App Service' task. You need to ensure that the deployment uses the Kudu REST API with ZIP deployment. Which value should you set for the 'packageForLinux' task input?

Your pipeline runs on a Microsoft-hosted agent. You need to securely reference an Azure Key Vault secret in a pipeline variable without exposing the value in logs. Which variable group type should you use and how should you reference the secret?

You are designing a build pipeline for a .NET Core application. You need to ensure that the pipeline restores NuGet packages from both an Azure Artifacts feed and the public NuGet gallery. The pipeline must fail if a package is not found in either source. Which two actions must you take? (Select two.)

Drag and drop the steps to implement a disaster recovery plan for Azure App Service into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

You are designing a build pipeline for a Java application that uses Maven. The build must run unit tests and integration tests separately. You want to publish test results to Azure Pipelines. Which task configuration should you use?

Your release pipeline deploys to Azure App Service using deployment slots. You need to ensure that traffic is gradually shifted to the new slot over 30 minutes, and if performance issues occur, it should automatically roll back. Which deployment strategy should you implement?

You are configuring a branch policy for the main branch using the Azure DevOps REST API. The JSON above is the policy configuration. A developer pushes a new commit to an existing pull request. What happens to the existing approvals?

Exhibit

Refer to the exhibit.
```json
{
  "policies": [
    {
      "policy": {
        "name": "Require Pull Request Review",
        "isEnabled": true,
        "blocking": true,
        "settings": {
          "minimumApproverCount": 2,
          "creatorVoteCounts": false,
          "allowDownvotes": true,
          "resetOnPush": false
        }
      }
    }
  ]
}
```

Your build pipeline uses a self-hosted agent. The agent is running low on disk space. You need to clean up the agent's working directory after each build. Which option should you configure in the pipeline?

Your team uses GitHub for source control and Azure Pipelines for CI/CD. You need to trigger a pipeline automatically when a pull request is created against the main branch. Which trigger type should you configure in the YAML pipeline?

Refer to the exhibit. A developer pushes a commit to the main branch. Which stages will run?

Exhibit

Refer to the exhibit.
```yaml
# azure-pipelines.yml
trigger:
  branches:
    include:
      - main
      - develop

stages:
- stage: Build
  jobs:
  - job: BuildJob
    pool:
      vmImage: ubuntu-latest
    steps:
    - script: echo "Building..."

- stage: Test
  dependsOn: Build
  condition: eq(variables['Build.SourceBranch'], 'refs/heads/develop')
  jobs:
  - job: TestJob
    pool:
      vmImage: ubuntu-latest
    steps:
    - script: echo "Testing..."
```

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Design and implement build and release pipelines sessions

Start a Design and implement build and release pipelines only practice session

Every question in these sessions is drawn from the Design and implement build and release pipelines domain — nothing else.

Related practice questions

Related AZ-400 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the AZ-400 exam test about Design and implement build and release pipelines?
You must be able to design a multi-stage YAML pipeline or GitHub Actions workflow that deploys sequentially to Dev, Test, and Prod with approvals, correct triggers, caching, and artifacts. The most important thing is matching triggers and approval placement to the stated deployment requirement.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Design and implement build and release pipelines questions in a focused session?
Yes — the session launcher on this page draws every question from the Design and implement build and release pipelines domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other AZ-400 topics?
Use the topic links above to move to related areas, or go back to the AZ-400 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the AZ-400 exam covers. They are not copied from any real exam or dump site.