Enforcing Patched Self-Hosted Agents with a Custom Capability Demand
Your team uses Azure Pipelines for CI/CD. You need to enforce that all pipeline runs use approved agents from a specific agent pool with the latest security patches. The agents are self-hosted on Azure VMs. What should you implement?
Quick Answer
Adding a demand for a custom agent capability — something like SecurityPatchLevel = latest that only patched, approved agents carry — restricts pipeline execution to agents meeting that requirement. Agent pool permissions and deployment pools control who can access or assign agents, not which specific agents a pipeline is allowed to run on.
⚠ Common exam trap
The trap is that candidates may think that using a dedicated agent queue or deployment pool will automatically limit which agents can run the pipeline. However, without a custom capability demand, any agent in the pool could be matched to the job. The correct approach is to define a custom capability for 'SecurityPatchLevel' or similar and add a demand to the pipeline.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Add a demand on the agent for a custom capability that only approved agents have
By adding a demand for a custom capability (e.g., 'SecurityPatchLevel = latest') on the pipeline, only agents that possess that capability can run the pipeline. This allows you to enforce that only approved, patched agents are used. Option C is incorrect because 'setting an agent pool to use a specific agent queue with an isolation scope' is not a recognized Azure Pipelines feature; agent pools use demands, not isolation scopes, to filter agents. Options A and B are also incorrect because configuring pool permissions or creating a deployment pool does not enforce that only agents with specific patches are used; they only control access or assignment but not the selection logic based on capabilities.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure pipeline permissions for the agent pool
Why it's wrong here
Pipeline permissions on an agent pool only grant or deny a pipeline's authorisation to use that pool; they neither force every run onto it nor apply security patches. It is tempting because permissions gate pool access, but they would be correct when restricting which pipelines may consume a shared pool.
- ✗
Create a deployment pool and assign the agents to it
Why it's wrong here
Deployment pools group target servers for deployment groups, not build or release agents, so they cannot enforce approved agents for pipeline runs. It is tempting because deployment pools also organise self-hosted machines, and would be correct for deploying to VM targets rather than running pipelines.
- ✗
Set the agent pool to use a specific agent queue with an isolation scope
Why it's wrong here
An isolation scope on an agent queue does not enforce which pool a pipeline uses, nor does it patch the self-hosted VMs. It is tempting because scopes restrict queue visibility, but isolation would be correct when preventing one project's pipelines from seeing another project's queues.
- ✓
Add a demand on the agent for a custom capability that only approved agents have
Why this is correct
A custom capability demand restricts pipeline job placement to self-hosted agents that carry that capability, so only approved, patched agents in the specified pool run the pipeline. This satisfies the requirement to enforce use of approved agents with current security patches.
Go deeper
Related to this question
Learn chapter
Implementing Deployment Patterns and Strategies
Key term
Feature
A feature is a distinct unit of functionality that delivers value to the user, often managed and tracked throughout the software development lifecycle.
Key term
Pipeline
A pipeline is an automated series of steps that takes code from development to production, ensuring quality and speed.
About these practice questions
One of 696 original AZ-400 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on AZ-400
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Your build pipeline runs on a self-hosted agent pool. You need to ensure that only authorized pipelines can use these agents. Which security measure should you implement?
medium- ✓ A.Set permissions on the agent pool
- B.Use agent tokens
- C.Use variable groups
- D.Configure agent queues
Why A: In Azure DevOps, agent pool security is controlled through the pool's permissions. By setting permissions on the agent pool, you can restrict which projects, pipelines, or users are allowed to use the agents, ensuring only authorized pipelines can run on them. This is the direct, built-in mechanism for securing a self-hosted agent pool.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-400 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-400 exam.