Skip to content

Develop a security and compliance plan Questions

Practice questions for Develop a security and compliance plan topic in Microsoft Certified: DevOps Engineer Expert. 27 questions covering this domain.

27 questions8 easy14 medium5 hard
Q1
hard

A team converts an Azure service connection to workload identity federation, but one pipeline task still fails to authenticate. What is the most likel...

Q2
medium

A team is creating a new Azure Resource Manager service connection for Azure Pipelines. Which authentication method does Microsoft recommend for new c...

Q3
medium

A project administrator wants to reduce exposure from an Azure service connection. What is the better practice for pipeline authorization?

Q4
medium

A team needs to store a certificate file for signing during deployment. Which statement about Azure Pipelines secure files is correct?

Q5
easy

Which statement correctly compares system-assigned and user-assigned managed identities?

Q6
easy

What is the relationship between a Microsoft Entra application object and a service principal?

Q7
medium

Which Dependabot capability automatically opens pull requests to update dependencies that have known security advisories?

Q8
medium

A GitHub Actions workflow uses OIDC to federate with Azure for a specific GitHub environment. Which subject claim format must the federated credential...

Q9
easy

Which GitHub Advanced Security feature performs static analysis to identify security vulnerabilities in source code?

Q10
medium

Developers in an organization keep accidentally pushing API keys to GitHub. Which GitHub Advanced Security feature blocks the git push at the protocol...

Q11
hard

A regulated team requires every production deployment from a GitHub repo to be approved by two specific reviewers and to wait at least 30 minutes afte...

Q12
easy

Which Microsoft service provides DevOps security posture management with connectors for GitHub and Azure DevOps?

Q13
medium

An organization wants to reduce ongoing Azure DevOps personal access token (PAT) usage and rotation overhead. Which Microsoft recommendation best meet...

Q14
medium

A GitHub organization owner wants to ensure that all repositories automatically enable Dependabot security updates when a vulnerability is detected. W...

Q15
medium

A platform engineer wants to scan container images for OS-level vulnerabilities as part of a GitHub Actions pipeline before pushing to a registry. Whi...

Q16
hard

A security team requires that every open-source package added to an Azure Artifacts feed be reviewed for license compliance before it can be used in p...

Q17
easy

Which Azure Pipelines library object stores a collection of reusable name/value pairs (including secrets) that can be referenced by multiple pipelines...

Q18
hard

A team's GitHub Actions workflow needs the minimum possible permissions. The workflow reads repository contents and writes pull request comments only....

Q19
medium

An Azure DevOps project uses several Classic release pipelines that still reference service connections with client secrets. The security team wants t...

Q20
easy

Which GitHub Advanced Security feature alerts repository maintainers when a project dependency has a known security vulnerability listed in the GitHub...

Sign in to see all 27 questions

Create a free account to browse all questions — completely free during our launch phase.