AZ-400 sample questions with answers

10 free AZ-400 sample questions across the exam's domains, each with its answer and an explanation. No account needed.

AZ-400 sample questions

Microsoft Certified: DevOps Engineer Expert, Microsoft.

  1. Question 1

    Domain: Design and implement processes and communications

    Which Azure DevOps dashboard widget shows work items moving through workflow states over time so that bottlenecks are visible?

    1. Test Results Trend (Advanced)
    2. Sprint Burndown
    3. Cumulative Flow Diagram
    4. Velocity
    Show the answer

    Answer: C. Cumulative Flow Diagram

    The Cumulative Flow Diagram (CFD) charts the count of work items in each workflow state over time; a widening band signals a bottleneck in that state. Velocity and burndown widgets track iteration throughput, and Test Results Trend tracks test pass rates.

    Checked against: https://learn.microsoft.com/en-us/azure/devops/report/dashboards/cumulative-flow

  2. Question 2

    Domain: Design and implement a source control strategy

    Which Git command creates a new commit that reverses the changes of commit abc123 without rewriting history?

    1. git reset --hard abc123
    2. git revert abc123
    3. git rebase -i abc123
    4. git checkout abc123
    Show the answer

    Answer: B. git revert abc123

    git revert creates a new commit that undoes the specified commit, preserving history so it is safe on shared branches. git reset --hard moves the branch pointer and discards commits, which rewrites history.

    Checked against: https://learn.microsoft.com/en-us/azure/devops/repos/git/undo

  3. Question 3

    Domain: Design and implement build and release pipelines

    One Bicep template deploys dev, test and production, but SKU sizes and instance counts differ per environment.

    What is the best way to manage the per-environment values?

    1. Hard-code the values in the Bicep file and keep a separate copy of the template per environment
    2. Store the values in the pipeline's name property
    3. Use a .bicepparam file per environment and pass it with --parameters at deployment
    4. Use Complete mode so values are inferred
    Show the answer

    Answer: C. Use a .bicepparam file per environment and pass it with --parameters at deployment

    Bicep parameter files (.bicepparam or JSON) hold environment-specific values and are referenced at deployment time, keeping a single template. Copies of the template per environment create drift.

    Checked against: https://learn.microsoft.com/en-us/azure/azure-resource-manager/bicep/parameter-files

  4. Question 4

    Domain: Design and implement build and release pipelines

    Which Azure Pipelines task restores and saves a directory such as ~/.npm between runs using a key?

    1. Cache@2
    2. CopyFiles@2
    3. DownloadPipelineArtifact@2
    4. PublishPipelineArtifact@1
    Show the answer

    Answer: A. Cache@2

    The Cache task restores files matching the key from the pipeline cache at the start of the job and saves them at the end when the key does not exist yet, cutting package restore time. Artifacts tasks move outputs between jobs and runs, not caches.

    Checked against: https://learn.microsoft.com/en-us/azure/devops/pipelines/release/caching

  5. Question 5

    Domain: Design and implement build and release pipelines

    Which Bicep feature lets you reuse a set of resources from another file with parameters?

    1. Deployment scripts
    2. Variables
    3. Outputs
    4. Modules
    Show the answer

    Answer: D. Modules

    A Bicep module is another Bicep file (or a template spec or registry module) invoked with the module keyword and parameters, producing a nested deployment. Variables and outputs are single values and deployment scripts run arbitrary scripts.

    Checked against: https://learn.microsoft.com/en-us/azure/azure-resource-manager/bicep/modules

  6. Question 6

    Domain: Design and implement build and release pipelines

    A pipeline runs a Python test suite that writes a JUnit XML report. Reviewers want failing tests listed on the pull request and the pull request blocked when tests fail.

    Which configuration provides the required feedback?

    1. Publish the JUnit XML report as a pipeline artifact with PublishPipelineArtifact@1
    2. PublishTestResults@2 with failTaskOnFailedTests: true and a build validation policy
    3. Set continueOnError: true on the test step
    4. Pipe the test output to the console only
    Show the answer

    Answer: B. PublishTestResults@2 with failTaskOnFailedTests: true and a build validation policy

    Publishing results with failTaskOnFailedTests makes the run fail when any test fails and surfaces the failing tests in the Tests tab and on the pull request. Console output or an artifact does not fail the run or give a per-test view, and continueOnError hides failures.

    Checked against: https://learn.microsoft.com/en-us/azure/devops/pipelines/tasks/reference/publish-test-results-v2

  7. Question 7

    Domain: Design and implement build and release pipelines

    An architect must recommend configuration management technology: the team needs to provision networks, VMs and databases, and also enforce that specific Windows services are disabled inside each VM.

    Which recommendation is the most appropriate?

    1. Use Bicep or Terraform for Azure resources and Azure Machine Configuration for in-guest OS settings
    2. Use Machine Configuration for everything, including creating VMs
    3. Use Azure App Configuration to define virtual networks and store the Windows service settings
    4. Use ARM JSON templates for in-guest configuration
    Show the answer

    Answer: A. Use Bicep or Terraform for Azure resources and Azure Machine Configuration for in-guest OS settings

    Declarative templates such as Bicep or Terraform provision Azure resources, while in-guest settings (installed packages, registry keys, services) are the domain of Machine Configuration or DSC. Neither tool covers the other layer well.

    Checked against: https://learn.microsoft.com/en-us/azure/governance/machine-configuration/overview

  8. Question 8

    Domain: Design and implement build and release pipelines

    A pipeline's pass rate has dropped to 60% over the past month. Failures appear random and developers rerun jobs until they pass, wasting hours of agent time.

    Which action should the team take first?

    1. Disable all failing tests in the pipeline until the overall pass rate returns above 90%
    2. Increase the job timeout to 120 minutes
    3. Rerun every failed run manually
    4. Use pipeline Analytics to find top failing tests and mark flaky ones in flaky test management
    Show the answer

    Answer: D. Use pipeline Analytics to find top failing tests and mark flaky ones in flaky test management

    The pipeline analytics report breaks down pass rate by stage and task and lists top failing tests, which localises the problem; flaky test management then keeps flaky tests from failing runs while they are fixed. Disabling tests hides the problem and timeouts do not address failures.

    Checked against: https://learn.microsoft.com/en-us/azure/devops/pipelines/reports/pipelinereport

  9. Question 9

    Domain: Develop a security and compliance plan

    A GitHub Actions workflow deploys to Azure. Security policy requires that no long-lived cloud credentials are stored in GitHub secrets.

    Which configuration achieves this?

    1. Commit a service principal certificate into the repository
    2. Store an Azure user's credentials in an environment secret protected by required reviewers
    3. Grant id-token: write and use azure/login with an Entra federated credential (OIDC), storing only client, tenant and subscription IDs
    4. Store the service principal client secret as an encrypted repository secret and pass it to the azure/login action through the creds input
    Show the answer

    Answer: C. Grant id-token: write and use azure/login with an Entra federated credential (OIDC), storing only client, tenant and subscription IDs

    With OpenID Connect, GitHub issues a short-lived token that Entra exchanges for an access token using a federated credential; no secret is stored in GitHub. The identifiers stored are not secrets. A client secret would still be a long-lived credential.

    Checked against: https://docs.github.com/en/actions/deployment/security-hardening-your-deployments/configuring-openid-connect-in-azure

  10. Question 10

    Domain: Implement an instrumentation strategy

    An operations team needs guest-level CPU, memory and disk metrics plus a map of which processes on their Azure VMs talk to each other.

    What should be enabled?

    1. VM Insights with the Azure Monitor agent and Dependency agent on the virtual machines
    2. Application Insights availability tests
    3. Azure Monitor for Storage
    4. Container Insights with the Azure Monitor agent collecting node performance data
    Show the answer

    Answer: A. VM Insights with the Azure Monitor agent and Dependency agent on the virtual machines

    VM Insights deploys the Azure Monitor agent with a data collection rule and optionally the Dependency agent, providing guest performance charts (CPU, memory, disk, network) and a dependency map. Container Insights is for AKS and the other options monitor different resources.

    Checked against: https://learn.microsoft.com/en-us/azure/azure-monitor/vm/vminsights-overview

More practice

A 20-question practice sampler is free with an account; Pro adds the full question bank and timed mock exams.

AZ-400 course and practice exam: Microsoft Azure DevOps Engineer Expert: the exam guide, with the format, cost, pass mark and domains from the vendor.