AZ-400 sample questions with answers
10 free AZ-400 sample questions across the exam's domains, each with its answer and an explanation. No account needed.
AZ-400 sample questions
Microsoft Certified: DevOps Engineer Expert, Microsoft.
Question 1
Domain: Design and implement processes and communications
Which Azure DevOps dashboard widget shows work items moving through workflow states over time so that bottlenecks are visible?
- Test Results Trend (Advanced)
- Sprint Burndown
- Cumulative Flow Diagram
- Velocity
Show the answer
Answer: C. Cumulative Flow Diagram
The Cumulative Flow Diagram (CFD) charts the count of work items in each workflow state over time; a widening band signals a bottleneck in that state. Velocity and burndown widgets track iteration throughput, and Test Results Trend tracks test pass rates.
Checked against: https://learn.microsoft.com/en-us/azure/devops/report/dashboards/cumulative-flow
Question 2
Domain: Design and implement a source control strategy
Which Git command creates a new commit that reverses the changes of commit abc123 without rewriting history?
- git reset --hard abc123
- git revert abc123
- git rebase -i abc123
- git checkout abc123
Show the answer
Answer: B. git revert abc123
git revert creates a new commit that undoes the specified commit, preserving history so it is safe on shared branches. git reset --hard moves the branch pointer and discards commits, which rewrites history.
Checked against: https://learn.microsoft.com/en-us/azure/devops/repos/git/undo
Question 3
Domain: Design and implement build and release pipelines
One Bicep template deploys dev, test and production, but SKU sizes and instance counts differ per environment.
What is the best way to manage the per-environment values?
- Hard-code the values in the Bicep file and keep a separate copy of the template per environment
- Store the values in the pipeline's name property
- Use a .bicepparam file per environment and pass it with --parameters at deployment
- Use Complete mode so values are inferred
Show the answer
Answer: C. Use a .bicepparam file per environment and pass it with --parameters at deployment
Bicep parameter files (.bicepparam or JSON) hold environment-specific values and are referenced at deployment time, keeping a single template. Copies of the template per environment create drift.
Checked against: https://learn.microsoft.com/en-us/azure/azure-resource-manager/bicep/parameter-files
Question 4
Domain: Design and implement build and release pipelines
Which Azure Pipelines task restores and saves a directory such as ~/.npm between runs using a key?
- Cache@2
- CopyFiles@2
- DownloadPipelineArtifact@2
- PublishPipelineArtifact@1
Show the answer
Answer: A. Cache@2
The Cache task restores files matching the key from the pipeline cache at the start of the job and saves them at the end when the key does not exist yet, cutting package restore time. Artifacts tasks move outputs between jobs and runs, not caches.
Checked against: https://learn.microsoft.com/en-us/azure/devops/pipelines/release/caching
Question 5
Domain: Design and implement build and release pipelines
Which Bicep feature lets you reuse a set of resources from another file with parameters?
- Deployment scripts
- Variables
- Outputs
- Modules
Show the answer
Answer: D. Modules
A Bicep module is another Bicep file (or a template spec or registry module) invoked with the module keyword and parameters, producing a nested deployment. Variables and outputs are single values and deployment scripts run arbitrary scripts.
Checked against: https://learn.microsoft.com/en-us/azure/azure-resource-manager/bicep/modules
Question 6
Domain: Design and implement build and release pipelines
A pipeline runs a Python test suite that writes a JUnit XML report. Reviewers want failing tests listed on the pull request and the pull request blocked when tests fail.
Which configuration provides the required feedback?
- Publish the JUnit XML report as a pipeline artifact with PublishPipelineArtifact@1
- PublishTestResults@2 with failTaskOnFailedTests: true and a build validation policy
- Set continueOnError: true on the test step
- Pipe the test output to the console only
Show the answer
Answer: B. PublishTestResults@2 with failTaskOnFailedTests: true and a build validation policy
Publishing results with failTaskOnFailedTests makes the run fail when any test fails and surfaces the failing tests in the Tests tab and on the pull request. Console output or an artifact does not fail the run or give a per-test view, and continueOnError hides failures.
Checked against: https://learn.microsoft.com/en-us/azure/devops/pipelines/tasks/reference/publish-test-results-v2
Question 7
Domain: Design and implement build and release pipelines
An architect must recommend configuration management technology: the team needs to provision networks, VMs and databases, and also enforce that specific Windows services are disabled inside each VM.
Which recommendation is the most appropriate?
- Use Bicep or Terraform for Azure resources and Azure Machine Configuration for in-guest OS settings
- Use Machine Configuration for everything, including creating VMs
- Use Azure App Configuration to define virtual networks and store the Windows service settings
- Use ARM JSON templates for in-guest configuration
Show the answer
Answer: A. Use Bicep or Terraform for Azure resources and Azure Machine Configuration for in-guest OS settings
Declarative templates such as Bicep or Terraform provision Azure resources, while in-guest settings (installed packages, registry keys, services) are the domain of Machine Configuration or DSC. Neither tool covers the other layer well.
Checked against: https://learn.microsoft.com/en-us/azure/governance/machine-configuration/overview
Question 8
Domain: Design and implement build and release pipelines
A pipeline's pass rate has dropped to 60% over the past month. Failures appear random and developers rerun jobs until they pass, wasting hours of agent time.
Which action should the team take first?
- Disable all failing tests in the pipeline until the overall pass rate returns above 90%
- Increase the job timeout to 120 minutes
- Rerun every failed run manually
- Use pipeline Analytics to find top failing tests and mark flaky ones in flaky test management
Show the answer
Answer: D. Use pipeline Analytics to find top failing tests and mark flaky ones in flaky test management
The pipeline analytics report breaks down pass rate by stage and task and lists top failing tests, which localises the problem; flaky test management then keeps flaky tests from failing runs while they are fixed. Disabling tests hides the problem and timeouts do not address failures.
Checked against: https://learn.microsoft.com/en-us/azure/devops/pipelines/reports/pipelinereport
Question 9
Domain: Develop a security and compliance plan
A GitHub Actions workflow deploys to Azure. Security policy requires that no long-lived cloud credentials are stored in GitHub secrets.
Which configuration achieves this?
- Commit a service principal certificate into the repository
- Store an Azure user's credentials in an environment secret protected by required reviewers
- Grant id-token: write and use azure/login with an Entra federated credential (OIDC), storing only client, tenant and subscription IDs
- Store the service principal client secret as an encrypted repository secret and pass it to the azure/login action through the creds input
Show the answer
Answer: C. Grant id-token: write and use azure/login with an Entra federated credential (OIDC), storing only client, tenant and subscription IDs
With OpenID Connect, GitHub issues a short-lived token that Entra exchanges for an access token using a federated credential; no secret is stored in GitHub. The identifiers stored are not secrets. A client secret would still be a long-lived credential.
Checked against: https://docs.github.com/en/actions/deployment/security-hardening-your-deployments/configuring-openid-connect-in-azure
Question 10
Domain: Implement an instrumentation strategy
An operations team needs guest-level CPU, memory and disk metrics plus a map of which processes on their Azure VMs talk to each other.
What should be enabled?
- VM Insights with the Azure Monitor agent and Dependency agent on the virtual machines
- Application Insights availability tests
- Azure Monitor for Storage
- Container Insights with the Azure Monitor agent collecting node performance data
Show the answer
Answer: A. VM Insights with the Azure Monitor agent and Dependency agent on the virtual machines
VM Insights deploys the Azure Monitor agent with a data collection rule and optionally the Dependency agent, providing guest performance charts (CPU, memory, disk, network) and a dependency map. Container Insights is for AKS and the other options monitor different resources.
Checked against: https://learn.microsoft.com/en-us/azure/azure-monitor/vm/vminsights-overview
More practice
A 20-question practice sampler is free with an account; Pro adds the full question bank and timed mock exams.
AZ-400 course and practice exam: Microsoft Azure DevOps Engineer Expert: the exam guide, with the format, cost, pass mark and domains from the vendor.