Microsoft Certified:DevOps Engineer Expert
Domain 4Objective 3
Automate Security and Compliance Scanning AZ-400 Practice Questions (Page 5)
Part of the Develop a security and compliance plan domain, which makes up ~19% of our current practice bank. Microsoft does not publish an official question count, but from its 140-minute exam (~55–95 total, ~10–18 in this domain), expect 3–6 from this objective — we provide 32 practice questions to prepare you well beyond it. (estimate)
32questions here
7free pages
6concepts
Questions 21–25
- 21
A company uses GitHub Enterprise Cloud for a Node.js application. The security team wants to automatically detect known vulnerabilities in the npm dependencies during the development cycle. They also want to receive alerts in the GitHub Security tab. What should you configure?
Select an answer first - 22
A DevOps team is designing a security scanning strategy for their CI/CD pipeline. They need to identify known vulnerabilities in third-party libraries, detect hardcoded credentials, and ensure open-source licenses are compliant. Which combination of scanning types addresses these three requirements?
Select an answer first - 23
An organization uses GitHub Enterprise Cloud and wants to centralize security findings from multiple repositories into Microsoft Defender for Cloud. They also want to track the security posture of their DevOps environment. What should you configure?
Select an answer first - 24
Which GitHub feature can automatically create pull requests to update vulnerable dependencies to a patched version?
Select an answer first - 25
A development team wants to implement a comprehensive security scanning strategy for their GitHub repository. They need to scan for secrets, code vulnerabilities, and dependency vulnerabilities. What is the most efficient way to achieve this?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Microsoft. “AZ-400” is a trademark of its owner, used for identification only.