AZ-400 sample questions with answers

10 free practice questions for the Microsoft Certified: DevOps Engineer Expert exam. Try each one, then open the answer to see why the right option wins and every other option loses.

Question 1Design and implement processes and communications

Woodgrove Bank must prove to a regulator that every user story released in a quarter was covered by at least one passing test, and must show the evidence per story rather than per test run. The team uses Azure Boards, Azure Test Plans, and automated tests published from a YAML pipeline. What should you implement?

  1. A.

    Create requirement-based test suites that link test cases to the user stories, and add the Requirements quality widget to the team dashboard.

  2. B.

    Tag every automated test with the identifier of the story it covers, export the test run summary to a CSV file after each release, and keep the files in a compliance folder for the auditor.

  3. C.

    Enable code coverage publishing in the pipeline and set a build validation policy with a minimum coverage threshold.

  4. D.

    Add the Test results trend (Advanced) widget to the dashboard and filter it by the release pipeline.

Show answer

Answer: A

Requirement-based test suites bind test cases to work items, and the Requirements quality widget reports pass or fail evidence for each linked requirement.

  • A. Requirement-based suites create Tested By links from test cases to stories, and the Requirements quality widget reports outcomes per story.
  • B. Tag-and-export is manual bookkeeping outside the work item graph; it creates no durable link and is not reproducible for an audit.
  • C. Code coverage proves which code executed, not which requirement was verified, and a threshold policy produces no requirement-level evidence.
  • D. The trend widget aggregates results per pipeline over time and offers no pivot by user story, so it cannot show per-requirement evidence.
Question 2Design and implement processes and communications

Litware has 40 repositories in a GitHub Enterprise Cloud organization with GitHub Advanced Security enabled. The security lead needs one continuously refreshed view that shows which repositories have code scanning, secret scanning, and Dependabot alerts enabled, together with the count of open alerts by severity across the organization. Administrative effort must be minimal. What should you use?

  1. A.

    A scheduled GitHub Actions workflow in each repository that calls the REST API and commits a CSV file to a reporting repository

  2. B.

    The organization-level security overview, using its overview and coverage views

  3. C.

    An Azure Boards dashboard with query tiles that count bugs tagged security across the connected projects

  4. D.

    The Dependabot alerts tab of each repository, reviewed weekly by the security lead

Show answer

Answer: B

Security overview at organization scope already aggregates alert counts and per-repository enablement for code scanning, secret scanning and Dependabot with no custom tooling.

  • A. Reimplementing reporting with per-repository workflows and CSV commits is substantial custom tooling duplicating a built-in view.
  • B. Security overview aggregates open alerts by severity and shows per-repository enablement for all three features with no custom code.
  • C. Boards counts work items, so it only reflects alerts someone manually converted into bugs, which is incomplete and lagging.
  • D. Per-repository tabs give no organization-wide aggregate and require 40 manual visits, failing the minimal effort constraint.
Question 3Design and implement processes and communications

A programme manager at Tailwind Traders must see on one timeline which features each of nine teams plans to deliver in each of the next four sprints, and must be able to see where one team's feature depends on another team's feature. Which should you use?

  1. A.

    A query tile for each of the nine teams that counts features in the next four iteration paths, added to one project dashboard.

  2. B.

    A delivery plan that includes the nine teams and shows dependency lines between their work items.

  3. C.

    A cumulative flow diagram widget for each of the nine teams, added to one project dashboard so that the timelines can be compared side by side.

  4. D.

    A sprint burndown widget for each of the nine teams, added to one project dashboard and refreshed at the start of each sprint.

Show answer

Answer: B

Delivery plans are the only Azure Boards view that lays several teams' backlogs against a shared iteration timeline and draws dependencies between their items.

  • A. A query tile reduces each team to a count, discarding which features are planned, their sequence and any dependency between them.
  • B. Delivery plans place several teams' backlogs on one iteration timeline and draw dependency lines between linked items, including unsatisfied ones.
  • C. A cumulative flow diagram is a historical view of state counts for one team and shows neither a forward plan nor dependencies.
  • D. Sprint burndown covers remaining work in the current sprint for one team, so it cannot show four sprints ahead or span nine teams.
Question 4Design and implement processes and communications

Litware hosts its repositories on an on-premises GitHub Enterprise Server instance and plans work in Azure DevOps Services. Developers must be able to link commits and pull requests to work items with AB# mentions. How should you configure the connection?

  1. A.

    Create a service hook subscription in Azure DevOps that posts work item events to the GitHub Enterprise Server instance.

  2. B.

    Import each GitHub Enterprise Server repository into Azure Repos, and link work items to the imported copies instead.

  3. C.

    Add a GitHub Enterprise Server connection in Project settings that authenticates with a personal access token, and make the server reachable from Azure DevOps Services.

  4. D.

    Install the Azure Boards app from GitHub Marketplace onto the GitHub Enterprise Server instance, and add the resulting connection in Project settings.

Show answer

Answer: C

Azure Boards connects to a GitHub Enterprise Server instance with a personal access token, and the server must be reachable from Azure DevOps Services.

  • A. A service hook sends Azure DevOps events outward to another system and creates no work item links from commits or pull requests.
  • B. Importing the repositories moves the code and creates a duplicate to reconcile, which the requirement does not ask for.
  • C. A GitHub Enterprise Server connection uses the server URL with a personal access token, and the instance must be reachable from Azure DevOps Services.
  • D. The Azure Boards app in GitHub Marketplace is a GitHub.com application and is not installed onto an Enterprise Server instance.
Question 5Design and implement processes and communications

An internal system at Contoso must process every work item created event from an Azure DevOps project. The system is taken offline for several hours each month for patching, and no event may be lost while it is down. What should you configure?

  1. A.

    A team notification subscription that sends an email to a shared mailbox the system monitors.

  2. B.

    A service hook subscription that uses the Azure Service Bus consumer, so that events are queued until the system reads them.

  3. C.

    A service hook subscription that uses the Web Hooks consumer, targeting the system's HTTPS endpoint.

  4. D.

    A scheduled job in the system that queries the work item tracking REST API every minute for items created since the last poll.

Show answer

Answer: B

The Azure Service Bus service hook consumer publishes events to a queue or topic that retains them until the consumer reads, which survives a planned outage.

  • A. Notification subscriptions deliver human-readable email to people and are not a structured, guaranteed integration channel.
  • B. The Azure Service Bus consumer publishes events to a queue or topic that retains them until the consumer reads, so a planned outage loses nothing.
  • C. The Web Hooks consumer posts directly to an endpoint and abandons the delivery after limited retries, so events are lost during a long outage.
  • D. Polling works but adds latency, consumes request quota continuously and requires the system to maintain its own reliable watermark.
Question 6Design and implement processes and communications

Northwind needs a 12-month trend of completed user stories by area path, refreshed daily and rendered in the corporate Power BI workspace next to finance data. Work is tracked in Azure Boards. Custom development must be minimal. What should you do?

  1. A.

    Create an Analytics view with a rolling 12-month history, then connect Power BI to it with the Azure DevOps Analytics views connector and set a daily refresh.

  2. B.

    Add a cumulative flow diagram widget to a project dashboard and grant the finance team read access to the Azure DevOps project.

  3. C.

    Schedule a pipeline that calls the work item tracking REST API, writes JSON to a storage account, and have Power BI read the JSON files from the account.

  4. D.

    Export the results of a shared work item query to a CSV file each month, and import the files into the Power BI workspace as a combined data set.

Show answer

Answer: A

Analytics views define a curated, historical work item data set that the Power BI Azure DevOps connector consumes directly with a scheduled refresh.

  • A. Analytics views carry historical work item data and are consumed directly by the Power BI Azure DevOps connector with a scheduled refresh and no code.
  • B. A dashboard widget renders inside Azure DevOps and cannot be placed alongside finance data in the corporate Power BI workspace.
  • C. The work item REST API returns current state rather than revision history, so the trend must be rebuilt from snapshots, and it is custom code where a connector exists.
  • D. A monthly CSV export is manual, cannot refresh daily, and accumulates files that must be reconciled by hand.
Question 7Design and implement processes and communications

A release notes script at Litware runs git log on the range between the previous release tag and HEAD. The repository completes pull requests with merge commits. The generated notes list each change several times: once as the pull request merge commit and once for every commit that was on the branch. You need one entry per pull request. What should you change?

  1. A.

    Add --no-merges, so that the merge commits are removed from the output.

  2. B.

    Add --oneline, so that each commit is printed on a single line.

  3. C.

    Add --first-parent, so that only the commits on the main line of history, which are the pull request merges, are listed.

  4. D.

    Add -n 50, so that only the most recent commits in the range are printed.

Show answer

Answer: C

Walking only the first parent of each merge lists the main line of history, which is one merge commit per completed pull request.

  • A. Removing merge commits leaves the individual branch commits, so work-in-progress subjects replace the pull request titles.
  • B. --oneline only shortens how each entry is printed and does not change which commits are selected.
  • C. Following only the first parent at each merge lists the target branch's main line, giving one merge commit per completed pull request.
  • D. A fixed count neither deduplicates entries nor respects the release boundary, and truncates large releases.
Question 8Design and implement processes and communications

A service at Proseware has a 99.95 percent monthly availability objective. Eighteen days into the month the service has already been unavailable for 31 minutes. The team is due to ship a large refactor. What should the agreed error budget policy cause the team to do?

  1. A.

    Ship the refactor as planned but lower the availability objective to 99.9 percent so that the month is no longer in breach.

  2. B.

    Pause feature releases and spend the remaining capacity on reliability work, because the budget for the month is effectively exhausted.

  3. C.

    Pause all deployments including reliability fixes until the next monthly period begins, so that no further budget can be consumed.

  4. D.

    Ship the refactor as planned, because the availability objective is measured over the month and there are still twelve days in which to recover the average.

Show answer

Answer: B

A 99.95 percent monthly objective allows about 21 minutes of downtime, so 31 minutes has already overspent the budget and the policy should stop feature releases.

  • A. Lowering the objective to match the outcome makes it meaningless and conceals a genuine reliability regression.
  • B. 99.95 percent of a 30-day month allows about 21 minutes of downtime, so 31 minutes has overspent the budget and the policy prioritizes reliability work.
  • C. Freezing reliability fixes as well as features blocks the work that restores the budget and leaves the service degraded.
  • D. Consumed unavailability cannot be recovered later in the period; a perfect remainder of the month still leaves the objective breached.
Question 9Design and implement processes and communications

Before sprint planning at Adventure Works, the scrum master must list every user story in the current sprint that has no child task. Which query should you create?

  1. A.

    A Work items and direct links query with User Story as the top-level filter, Task as the linked filter, and the option that returns only items which do not have the specified links.

  2. B.

    A flat list query filtered to Work Item Type equals User Story and Remaining Work equals zero, scoped to the current iteration.

  3. C.

    A flat list query filtered to Work Item Type equals User Story that uses the Was Ever operator on the State field to find stories that never became Active.

  4. D.

    A Tree of work items query filtered to User Story and Task, sorted so that stories with no children are grouped at the top of the results.

Show answer

Answer: A

Only the Work items and direct links query type can filter on the absence of a link, using the option that returns items which do not have the specified links.

  • A. Work items and direct links is the only query type with a link filter, and its do-not-have option returns exactly the stories with no child task.
  • B. Remaining Work of zero is a field condition that also matches stories whose tasks are finished, and returns nothing where effort is not tracked.
  • C. Was Ever inspects the history of a field value and says nothing about whether the story has linked tasks.
  • D. A tree query displays hierarchy but cannot filter on the absence of a child, and no sort order separates parentless stories.
Question 10Design and implement processes and communications

Six teams at Litware each need the same five flow widgets scoped to their own backlog. A leadership group needs one page that shows a roll-up and that nobody outside the group can edit. Dashboards must be maintained with the least effort. What should you do?

  1. A.

    Create a team dashboard for each team, use Copy dashboard to replicate the layout, and add a project dashboard for leadership whose edit permission is granted only to that group.

  2. B.

    Create a team dashboard for each team, and give every member of the leadership group Stakeholder access so that they cannot edit any dashboard in the project.

  3. C.

    Create six project dashboards, one for each team, and control who can change each widget by adding a security rule to the widget configuration.

  4. D.

    Create one project dashboard that holds all six teams' widgets, and ask each team to filter the page by its own area path when it opens the dashboard.

Show answer

Answer: A

Team dashboards inherit the team context that scopes the widgets, Copy dashboard replicates the layout, and a project dashboard carries its own edit permission for the leadership group.

  • A. Team dashboards supply the team context the flow widgets need, Copy dashboard avoids reconfiguring each one, and project dashboards carry their own edit permission.
  • B. Stakeholder is an organization-wide access level that restricts the user everywhere and does not make a particular dashboard read-only to others.
  • C. Permissions are set on the dashboard, not on individual widgets, so there is no per-widget security rule to configure.
  • D. Dashboards have no viewer-applied page filter; scope is configured per widget, so one shared page shows all six teams to everyone.

Keep going with 511 more AZ-400 questions

Free papers every day, in the real exam formats, with progress by exam domain. Unlock every paper and timed mock exam when you are ready.

AZ-400 sample questions with answers (10 free) · CertifyCloudx