AZ-400 Practice Question: Design and implement build and release pipelines
Which THREE are required components to implement a secure CI/CD pipeline using Azure Pipelines and GitHub?
⚠ Common exam trap
Many exam-takers assume a container registry is universally required, but it is only needed for container-based workflows, not for all secure CI/CD pipelines.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
An Azure service connection to authenticate to Azure resources.
Option A is correct because an Azure service connection (a service principal or workload identity federation stored in Azure DevOps) is the mechanism Azure Pipelines uses to authenticate to Azure subscriptions and deploy resources securely without embedding credentials in code. Option C is correct because a YAML pipeline definition with stages and jobs is the declarative pipeline artifact that Azure Pipelines executes to build, test, and deploy code in a repeatable, version-controlled manner. Option E is correct because branch protection rules requiring status checks to pass prevent unreviewed or failing code from being merged, enforcing quality and security gates in the GitHub workflow. Option B is not required because a container registry is only needed when the pipeline builds and stores Docker images, which is not a universal requirement for a secure CI/CD pipeline. Option D is not required and is in fact insecure, since storing a GitHub personal access token as a plain text variable exposes the secret; tokens should be kept in Azure Key Vault or a secret variable group instead.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
An Azure service connection to authenticate to Azure resources.
Why this is correct
A service connection is required for secure authentication to Azure resources, storing credentials or using workload identity federation so the pipeline can deploy without hard-coded secrets. It is a core component because every Azure-bound task needs a valid, authorized identity.
- ✗
A container registry to store Docker images.
Why it's wrong here
A container registry is only necessary if the pipeline builds and publishes Docker images; for typical application CI (e.g., .NET, Node, Python) it is not a required component. Secure CI can be implemented without any container registry by using hosted agents and artifact feeds.
- ✓
A YAML pipeline definition with stages and jobs.
Why this is correct
The YAML pipeline definition is the declarative code that defines triggers, stages, jobs, and steps, making the CI process auditable, version-controlled, and repeatable. It is required because without it there is no automated workflow to build, test, and validate code.
- ✗
A GitHub personal access token stored as a plain text variable.
Why it's wrong here
A GitHub personal access token is not a required component for secure CI, and storing one as a plain-text variable is a serious security anti-pattern. Plain-text variables are visible in pipeline logs and can be read by anyone with access to the pipeline settings, exposing credentials. Secure authentication to GitHub repositories is instead handled by Azure DevOps service connections (e.g., using OAuth or PATs stored as encrypted secrets), and for Azure resources you should use workload identity federation or service principals with secrets referenced from Azure Key Vault. Even if a PAT were used, it must be stored in a secret variable or variable group backed by Key Vault, not as plain text.
- ✓
Branch protection rules requiring status checks to pass.
Why this is correct
Branch protection rules enforce that pull requests cannot be merged unless required status checks (such as the CI pipeline) pass, providing a critical security and quality gate. They are required for secure CI because they prevent unvalidated code from reaching the main branch.
Go deeper
Related to this question
Learn chapter
Implementing a Build Pipeline
Key term
DevOps
DevOps is a set of practices that combines software development (Dev) and IT operations (Ops) to shorten the development lifecycle and deliver high-quality software continuously.
Key term
Azure DevOps
Azure DevOps is a Microsoft service that provides development tools for planning, building, testing, and deploying software applications using automated pipelines and collaboration features.
About these practice questions
This AZ-400 question is part of Courseiva's 696-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-400 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-400 exam.