20 free AZ-400 practice questions with answers and explanations, covering processes and communications, source control, build and release pipelines, security and compliance, and instrumentation across Azure DevOps and GitHub.
Study the full AZ-400 course, free to start.
Official AZ-400 study guide on Microsoft Learn
Question 1. You need to trace a production change back to its requirement, code review, and tests. What enables this?
Answer: A, End-to-end traceability linking work items, commits, PRs, builds, and releases. Linking work items to commits/PRs/builds/releases gives source, bug, and quality traceability.
Question 2. One release spans four repositories, and the team wants a single plan broken into two-week sprints. What should you set up?
Answer: B, An organisation-owned GitHub Project with an iteration field. Projects span repositories and iteration fields provide the time boxes. A milestone is scoped to a single repository, so four of them is four plans, not one.
Question 3. You want to visualise where work is piling up across board columns over time. Which chart helps?
Answer: C, A cumulative flow diagram. A cumulative flow diagram shows work-in-progress per state over time, exposing bottlenecks.
Question 4. You want to embed a rendered flowchart directly inside a project wiki page. Which syntax do you use?
Answer: D, Mermaid in Markdown. Azure DevOps wikis render Mermaid diagrams written inline in Markdown.
Question 5. In Azure Repos, how do you require two reviewers and a passing build before a PR can complete on main?
Answer: A, Configure a branch policy on main. Azure Repos branch policies enforce minimum reviewers, build validation, and more on protected branches (GitHub calls these branch protection rules).
Question 6. A repository is bloated and slow to clone because it stores large binary assets. What should you implement?
Answer: D, Git Large File Storage (LFS). Git LFS stores large binaries outside the main repo as pointers, keeping clones fast.
Question 7. A regulated product ships four times a year and has to keep patching version 8.2 while version 9.0 is being built. Which branching strategy fits, and what does it cost you?
Answer: A, Release branching, at the cost of landing every fix on the release branch and on main. A long-lived branch per release is what lets you patch 8.2 without shipping unfinished 9.0 work. The price is that every fix has to land in two places, which is precisely the overhead trunk-based strategies exist to avoid. Trunk-based suits continuous delivery, not a product with supported older versions in the field.
Question 8. A CI job on a very large repository spends most of its run time cloning, and it only ever needs the latest commit. What is the cheapest fix?
Answer: B, Use a shallow clone so only recent history is fetched. A shallow clone limits how much history is downloaded, which is exactly right for a CI job that only needs the latest commits. A partial clone is the other lever and keeps full history while fetching file contents on demand. Scalar helps a developer working in a large repo day to day, and LFS is for large binaries, not for source.
Question 9. Which is GitHub's integrated package hosting service?
Answer: A, GitHub Packages. GitHub Packages hosts packages tied to GitHub repos and Actions.
Question 10. A pipeline must use licensed software and reach an on-premises database on a private network. Which agent fits?
Answer: A, A self-hosted agent/runner. Self-hosted agents run on your infrastructure, allowing custom software and private connectivity.
Question 11. Which Azure Pipelines construct records deployment history and lets you apply runOnce/rolling/canary strategies against an environment?
Answer: C, A deployment job. Deployment jobs run against an environment, capture deployment history, and support deployment strategies.
Question 12. Old pipeline runs and artifacts are consuming storage indefinitely. What should you configure?
Answer: B, A retention policy for runs and artifacts. Retention policies automatically prune old runs and artifacts to control storage.
Question 13. A GitHub Actions job needs to comment on a PR in the same repo without any stored credential. What should it use?
Answer: B, The built-in GITHUB_TOKEN. The automatically provided, run-scoped GITHUB_TOKEN avoids storing any credential.
Question 14. You want GitHub Actions to deploy to Azure with no secret stored in the repo at all. Which approach?
Answer: B, Workload identity federation (OpenID Connect). OIDC workload identity federation issues short-lived tokens, so no secret is stored.
Question 15. GitHub detects a vulnerable open-source dependency and can open a PR to bump it. What is this?
Answer: D, Dependabot. Dependabot alerts on and can automatically update vulnerable dependencies.
Question 16. You ship a closed-source product. A scan flags a transitive dependency published under a strong copyleft licence. What is the risk being raised?
Answer: A, Distributing the product would oblige you to release your own source under the same licence. Strong copyleft propagates to derivative works you distribute. It does not forbid selling the software, it forbids keeping the combined source closed.
Question 17. Where are Azure Monitor logs stored and queried with KQL?
Answer: D, A Log Analytics workspace. Logs land in a Log Analytics workspace and are queried with Kusto Query Language.
Question 18. Which Azure Monitor experience gives targeted telemetry for AKS/container workloads?
Answer: D, Container Insights. Container Insights focuses on container/Kubernetes telemetry; VM Insights covers virtual machines.
Question 19. A developer never hears about failed GitHub Actions runs on a repository they contribute to, while a teammate hears about everything on it. Where is that difference set?
Answer: C, In each user's GitHub notification settings, which govern watching and whether Actions runs notify them. Notifications on GitHub are a per-user setting: they decide whether you watch a repository or only participate, whether GitHub Actions workflow runs notify you at all, and whether delivery is the web inbox, email or the mobile app.
Question 20. A request passes through several microservices and you need to find which one adds the latency. What do you use?
Answer: D, Distributed tracing in Application Insights. Distributed tracing follows the request across services to localise the slow component.
It's an expert-level exam, and build and release pipelines make up over half of it. It expects real experience with both Azure DevOps and GitHub, and many questions ask you to choose the best of several workable designs.
Most people studying part-time plan six to ten weeks, depending on how much of Azure DevOps and GitHub they use at work. Spend at least half of it on pipelines.
No. Microsoft exam questions are confidential, and sharing them breaks the agreement every candidate accepts. These are original questions written to the published skills outline, so they test the same knowledge in the same style.
You can enrol free with no card. Free accounts get the opening modules of every course; Pro (£9.99 a month, or £79.99 a year) unlocks every module, the full timed mock exam and an adaptive study plan.
Answer each one before you look at the explanation, and keep a list of the ones you get wrong. That list is your study plan: it's made of exactly the things you don't know yet.
CertBuddi is an independent study aid, not affiliated with or endorsed by Microsoft. These are original practice questions, not real exam questions.