AZ-400 exam dumps

AZ-400 practice question 232 of 306

Designing and Implementing Microsoft DevOps Solutions. Professional level, Microsoft. Free question with the correct answer and a full explanation.

AZ-400 Question 232

Select 2

You manage an Azure DevOps environment for an organization that utilizes an external QA team. The QA team needs the ability to create and manage test plans, execute test runs, and view build results, but they must not modify code or administer the project. Which two actions should you take to ensure the QA team has only the required permissions?

  1. A

    Add the QA team to the default Project Administrators group to avoid configuring test permissions individually.

  2. B

    Add the QA team to the default Readers group and assign additional permissions specific to test plan management.

  3. C

    Grant the QA team the Contribute permission at the repository level to streamline test execution.

  4. D

    Create a custom QA security group that includes Manage Test Plans and Publish Test Results permissions, and add the QA team to this group.

Show answer and explanation

Correct answers: B, D

Explanation

To enforce minimal permissions, you can leverage default groups like Readers to provide basic read access, then layer on only the permissions necessary for testing (Manage Test Plans, Publish Test Results). Creating a custom group for QA responsibilities (Option 4) or assigning specific test permissions to the Readers group (Option 2) are both effective strategies. For more details, refer to Microsoft documentation on Azure DevOps Project Permissions and Security Groups: https://learn.microsoft.com/azure/devops/organizations/security/permissions.

  • A. Incorrect.

    Option 1: Incorrect. Placing the QA team in the Project Administrators group grants them excessive permissions (such as the ability to alter project settings and manage code repositories). This fails the principle of least privilege.

  • B. Correct.

    Option 2: Correct. The default Readers group allows view access to build results and other project data. You can then selectively grant test-related permissions (e.g., Manage Test Plans) so they can create and manage test artifacts without affecting code or administrative settings.

  • C. Incorrect.

    Option 3: Incorrect. Contribute at the repository level would allow the QA team to modify repositories, which violates the requirement that they shouldn�t be able to change code.

  • D. Correct.

    Option 4: Correct. Creating a custom security group with granular permissions around testing (e.g., Manage Test Plans, Publish Test Results) lets the QA team run and manage test plans while blocking code changes and broader project administration.

Timed practice exam

Take a AZ-400 practice test under exam conditions

70 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam