Courseiva
mediumMultiple Choice

Why a Variable Group Can't Find a Secret That Exists in Key Vault

A company uses Azure DevOps for CI/CD. They have multiple pipelines that deploy to different environments. They want to ensure that secrets like API keys are not exposed in pipeline logs. What is the best approach?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a Variable Group linked to Azure Key Vault

Variable Groups linked to Azure Key Vault allow you to securely store secrets in Key Vault and reference them in pipelines without exposing the actual values in logs or output. Option A is incorrect: Azure App Configuration with Key Vault references is designed for application configuration, not for managing pipeline secrets directly. Option C is incorrect: Azure Kubernetes Service (AKS) secrets are specific to Kubernetes workloads and not intended for general pipeline secret management. Option D is incorrect: Pipeline variables marked as 'secret' are masked in logs, but they are still stored in Azure DevOps and lack the centralized security and auditing capabilities of Key Vault.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use Azure App Configuration with Key Vault references

    Why it's wrong here

    Azure App Configuration with Key Vault references is designed for application runtime configuration, not for Azure Pipelines variable resolution. While it can reference Key Vault secrets, the pipeline itself cannot natively consume those references as pipeline variables without custom tasks or API calls, adding overhead and an external dependency that does not integrate with the pipeline's variable model. In contrast, a Variable Group linked to Key Vault is a first-class Azure Pipelines construct that makes secrets available directly to tasks at runtime.

  • ✓

    Create a Variable Group linked to Azure Key Vault

    Why this is correct

    Creating a Variable Group linked to Azure Key Vault is the recommended approach because the Variable Group stores only references to secret names in Key Vault, not the secret values themselves. At pipeline runtime, Azure Pipelines fetches the actual secret values from Key Vault using a service connection, ensuring secrets never reside in pipeline definitions, logs, or the Azure DevOps database. This also provides centralized access control via Key Vault permissions, supports secret rotation, and integrates natively with pipeline consumers.

  • ✗

    Use Azure Kubernetes Service secrets

    Why it's wrong here

    Azure Kubernetes Service (AKS) secrets are designed to store sensitive configuration for workloads running inside a Kubernetes cluster, not for Azure DevOps pipeline execution. Pipeline tasks that need to authenticate to external services or deploy to AKS must retrieve secrets from Azure DevOps constructs like Variable Groups or service connections, so using AKS secrets would not make the secrets available to the pipeline at runtime and would create an unnecessary dependency on cluster access.

  • ✗

    Use pipeline variables marked as 'secret'

    Why it's wrong here

    Pipeline variables marked as 'secret' are masked in logs, but the underlying values are still stored in plaintext within the pipeline definition, whether in YAML or the classic UI. Anyone with edit permissions to the pipeline can read the actual secret value from the pipeline settings, and it remains at rest in Azure DevOps storage. This violates the principle of least privilege and increases exposure risk, whereas Key Vault-linked Variable Groups keep the secret value entirely out of the pipeline system.

About these practice questions

Courseiva writes every AZ-400 question from scratch — 696 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

4 more ways this is tested on AZ-400

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Your Azure DevOps pipeline uses a variable group to store secrets. The variable group is linked to a Key Vault. You need to use a secret variable in a pipeline task. How should you reference the secret in the YAML pipeline?

medium
  • A.Reference the variable as $(VariableName) but only in a script task using 'env' mapping.
  • B.Use the 'task.getVariable' method in a PowerShell script.
  • ✓ C.Reference the variable as $(VariableName) in the pipeline tasks.
  • D.Use the Azure Key Vault task to retrieve the secret and then reference the output variable.

Why C: When a variable group is linked to an Azure Key Vault, secret variables are automatically available in the pipeline. You can reference them directly using the standard $(VariableName) syntax in any pipeline task. No special task or script is required. Option A is incorrect because you do not need to restrict to script tasks or use 'env' mapping; the $(VariableName) works everywhere. Option B is incorrect because 'task.getVariable' is a scripting method used within tasks, not a YAML syntax. Option D is incorrect because the Azure Key Vault task is unnecessary; the variable group handles the retrieval automatically.

Variation 2. Your build pipeline uses a YAML template that references variables from a variable group. The variable group is linked to a library. You need to ensure that sensitive variables are not exposed in logs. Which THREE actions should you take?

hard
  • A.Set the variable group to 'Allow access to all pipelines'.
  • ✓ B.Store the secrets in Azure Key Vault and reference them in the variable group.
  • C.Use 'Write-Host' to output the variable values for debugging.
  • ✓ D.Mark the variables as 'secret' in the variable group.
  • ✓ E.Configure permissions on the library to restrict which pipelines can use the variable group.

Why B: To keep sensitive variables out of pipeline logs, you should store secrets in Azure Key Vault and reference them in a variable group (B), mark variables as secret in the variable group (D), and configure permissions on the library to restrict which pipelines can use the variable group (E). Key Vault integration and secret marking ensure that values are masked automatically, while restricting access limits the risk of unauthorized pipelines that could expose secrets.

Variation 3. Which THREE steps should you take to implement a secure CI/CD pipeline that uses secrets from Azure Key Vault?

hard
  • ✓ A.Use the Azure Key Vault task to download secrets as variables
  • ✓ B.Use secret variables in the pipeline that reference Key Vault secrets
  • C.Store secrets as plain text variables in the pipeline library
  • D.Hardcode secrets in the YAML file and use variables to mask them
  • ✓ E.Grant the build agent managed identity access to the Key Vault

Why A: The Azure Key Vault task in Azure Pipelines can download secrets as pipeline variables at runtime, allowing the pipeline to securely reference them without exposing the secret values in logs or configuration. This task authenticates to Key Vault using a service connection or managed identity, ensuring secrets are never stored in the pipeline definition.

Variation 4. You are reviewing a pipeline YAML file. The variable 'prod-db-password' is stored in a variable group linked to Azure Key Vault. However, the pipeline fails with an error that the secret cannot be accessed. What is the most likely cause?

medium
  • A.The YAML syntax for referencing the variable is incorrect.
  • ✓ B.The pipeline's authorized service principal lacks 'Get' permission on the Key Vault.
  • C.The variable group 'prod-variables' does not exist.
  • D.The secret name in Key Vault does not match 'prod-db-password'.

Why B: The most likely cause is that the pipeline's authorized service principal lacks 'Get' permission on the Key Vault. When a variable group is linked to Azure Key Vault, Azure Pipelines uses a service principal (the pipeline's identity) to retrieve secrets. Even if the variable group and secret name are correct, the pipeline will fail if the service principal does not have the 'Get' secret permission in the Key Vault access policy. This is a common misconfiguration because the variable group link only establishes the mapping, not the actual access rights.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-400 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-400 exam.