Which TWO actions should you take to ensure that your Azure DevOps pipeline securely manages secrets?
Azure Key Vault variable groups securely store secrets in Azure Key Vault and link them to pipelines via variable group metadata, enabling pipelines to fetch secrets at runtime without writing them into YAML or repository files; access is governed by Azure RBAC and Key Vault access policies.
Why this answer
Option A is correct because linking an Azure Key Vault to a variable group lets the pipeline fetch secrets at runtime from Key Vault, so the secret values are never stored in the pipeline definition and access is governed by Key Vault access policies or RBAC. Option D is correct because secret variables defined in the pipeline UI or in variable groups are encrypted at rest by Azure DevOps, masked in logs, and not exposed in the YAML source, which is the supported way to hold secrets the pipeline needs directly. Option B is wrong because enabling scripts to access the system token and printing secrets to logs deliberately exposes credentials, defeating masking and enabling token theft.
Option C is wrong because secrets committed in the YAML pipeline file are stored in source control in plain text and visible to anyone with repo access. Option E is wrong because storing secrets as plain text in the repository exposes them to all readers of the repo and to its history, with no encryption or masking.
Exam trap
AZ-400 often tests the temptation to 'debug' by printing secrets or storing them in YAML — candidates must recognize that only Key Vault variable groups and UI-defined secret variables are secure.