Courseiva

AZ-400 Practice Question: Design and implement build and release pipelines

You have a YAML pipeline that builds a container image and pushes it to Azure Container Registry (ACR). The pipeline uses a Docker task to build and push the image. You need to ensure that the image is tagged with both the build ID and the latest tag, but only when the build is from the main branch. Which approach should you use?

⚠ Common exam trap

The trap here is overcomplicating the solution by using separate tasks or CLI commands to add tags, when the Docker task natively supports multiple tags in one step.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use a single Docker task with the command buildAndPush and specify multiple tags in the tags input, and add a condition to the task to run only for the main branch.

The Docker task's buildAndPush command accepts multiple tags in the tags input, allowing both the build ID and latest to be applied in a single build and push operation. Adding a condition to the task ensures it only runs for the main branch. This is the most efficient and maintainable solution.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Use a single Docker task with the command buildAndPush and specify multiple tags in the tags input, and add a condition to the task to run only for the main branch.

    Why this is correct

    The Docker task's buildAndPush command supports multiple tags via a comma-separated list in the tags input. You can specify both $(Build.BuildId) and latest. By adding a condition such as eq(variables['Build.SourceBranch'], 'refs/heads/main'), the task will only execute for the main branch, ensuring the tags are applied only in that case. This is the most straightforward and supported method.

  • ✗

    Use two separate Docker tasks: one to build and push with the build ID tag, and another to build and push with the latest tag, each with its own condition.

    Why it's wrong here

    Using two separate tasks would rebuild the image twice, which is inefficient and could lead to inconsistencies if the source changes between tasks. It also doubles the push operations. The Docker task can handle multiple tags in one build, so this approach is unnecessary and less reliable.

  • ✗

    Use a Docker task to build and push with the build ID tag, then use an Azure CLI task to run az acr repository update to add the latest tag, with a condition on the CLI task.

    Why it's wrong here

    While the Azure CLI can update tags, this adds complexity and requires additional permissions. The Docker task already supports multiple tags, so using a separate CLI task is redundant. It also introduces a dependency on the Azure CLI task and may not be as atomic as a single build and push operation.

  • ✗

    Use a Docker task to build and push with the latest tag, then use a script to retag the image with the build ID using docker tag and docker push, with a condition on the script.

    Why it's wrong here

    This approach requires running docker tag and docker push manually, which is more error-prone than using the built-in tags input. It also assumes the Docker daemon is available on the agent and that the image is present locally. The Docker task's buildAndPush with multiple tags is simpler and more reliable.

About these practice questions

This AZ-400 question is part of Courseiva's 696-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This AZ-400 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-400 exam.