Courseiva

Two Benefits Deployment Groups Have Over Individual VM Targeting

Which TWO are benefits of using deployment groups in Azure Pipelines compared to using individual virtual machines?

Quick Answer

Deployment groups let one pipeline run target every machine in the group at once, enabling rolling deployments with per-machine health checks — compared to configuring each individual VM separately in the pipeline, deployment groups centralize target management and let you reuse the same group definition across multiple releases.

⚠ Common exam trap

It's easy for candidates to confuse deployment groups with Azure VM scale sets, leading candidates to incorrectly associate automatic scaling or cost-saving shutdown features with deployment groups, when those are separate Azure services.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Simplified targeting of multiple machines with a single pipeline run.

Option D is correct because deployment groups let a single pipeline job target a logical set of machines (defined by tags), so one pipeline run can deploy to many VMs without enumerating each machine individually. Option E is correct because deployment groups natively support rolling deployments, where the agent on each target machine runs the deployment steps and the pipeline can perform health checks and stop the rollout if a machine fails. Option A is not a deployment group feature; secrets such as connection strings are handled by Azure Key Vault, variable groups, or secret variables, not by deployment groups themselves. Option B is incorrect because deployment groups do not shut down VMs to save cost; they only orchestrate deployment to registered machines. Option C is incorrect because automatic VM scaling is provided by VM scale sets or autoscale settings, not by deployment groups.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Built-in secrets management for connection strings.

    Why it's wrong here

    Deployment groups orchestrate agent installation and rolling deployment across target machines; they provide no secret store. Secrets management is handled by Azure Key Vault or pipeline variable groups. This option is tempting because deployment groups do carry per-target configuration, but that is machine targeting, not credential protection.

  • ✗

    Reduced cost because VMs are shut down when not in use.

    Why it's wrong here

    Deployment groups register existing machines as agents and do not manage their power state, so no shutdown or cost saving occurs. Cost reduction comes from scale sets or auto-shutdown schedules. It is tempting because deployment groups target many machines, which sounds economical, yet they simply tag and deploy to whatever is already running.

  • ✗

    Automatic scaling of virtual machines based on load.

    Why it's wrong here

    Deployment groups perform no autoscaling; they deploy to a fixed set of registered target machines. Autoscaling is provided by virtual machine scale sets or AKS node pools. It is tempting because deployment groups handle many machines, implying elasticity, but membership changes only when machines are manually registered or removed.

  • ✓

    Simplified targeting of multiple machines with a single pipeline run.

    Why this is correct

    Deployment groups register multiple target machines as one logical set, letting a single pipeline run fan out to all of them. This removes the need to define and maintain separate pipeline stages or jobs per machine.

  • ✓

    Rolling deployment support with health checks.

    Why this is correct

    Deployment groups orchestrate releases across tagged target machines, so Pipelines can pause between batches and run health checks before proceeding. This satisfies the stem's rolling-update benefit, which individual VM targeting cannot deliver because each machine deploys independently without coordinated gating.

About these practice questions

One of 696 original AZ-400 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on AZ-400

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. You are creating a release pipeline that uses Azure Pipelines to deploy to multiple virtual machines. You need to ensure that the deployment runs on each machine in parallel. Which deployment strategy should you use?

easy
  • A.Blue-green deployment
  • B.Canary deployment
  • C.Rolling deployment
  • ✓ D.Run once deployment with parallel execution

Why D: The requirement is to deploy to multiple virtual machines in parallel, which is achieved by configuring a 'run once' deployment strategy with parallel execution in Azure Pipelines. This strategy uses the deployment group's parallel execution settings to run the deployment job simultaneously on all target machines, ensuring each machine receives the deployment at the same time.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-400 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-400 exam.