Microsoft Certified:DevOps Engineer Expert
Domain 4Objective 3
Automate Security and Compliance Scanning AZ-400 Practice Questions (Page 6)
Part of the Develop a security and compliance plan domain, which makes up ~19% of our current practice bank. Microsoft does not publish an official question count, but from its 140-minute exam (~55–95 total, ~10–18 in this domain), expect 3–6 from this objective — we provide 32 practice questions to prepare you well beyond it. (estimate)
32questions here
7free pages
6concepts
Questions 26–30
- 26
A GitHub repository uses a `package-lock.json` file. The security team wants to automatically receive alerts when a transitive dependency has a known vulnerability and also want to see the dependency graph. What should you enable?
Select an answer first - 27
A development team builds a container image and pushes it to Azure Container Registry. They want to automatically scan the image for vulnerabilities before it is deployed to production. What should you configure?
Select an answer first - 28
What is the main benefit of integrating GitHub Advanced Security findings with Microsoft Defender for Cloud?
Select an answer first - 29
In a GitHub Actions workflow, which action is used to run CodeQL analysis on the code inside a container?
Select an answer first - 30
Which type of security scanning is specifically designed to detect hardcoded passwords, API keys, and other sensitive information that might be committed to a source repository?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Microsoft. “AZ-400” is a trademark of its owner, used for identification only.