AZ-400 exam dumps

AZ-400 practice question 234 of 306

Designing and Implementing Microsoft DevOps Solutions. Professional level, Microsoft. Free question with the correct answer and a full explanation.

AZ-400 Question 234

Single answer

Your organization is consolidating several teams into a single project in Azure DevOps. You want only DevOps Engineers to modify and manage build pipelines, while the entire development team should be able to queue or run these pipelines. All other employees should only be able to view pipeline results without the ability to queue or alter anything. Which approach meets these requirements?

  1. A

    Add DevOps Engineers to the Build Administrators group, grant the Dev team 'Queue builds' permission, and assign only 'View builds' permission to all other users.

  2. B

    Create a custom security group for DevOps Engineers, but assign 'Edit build pipeline' permissions to all users in the Dev team as well.

  3. C

    Grant all project contributors 'Edit build pipeline' permission to simplify the process, and rely on separate code repository permissions to restrict other actions.

  4. D

    Rely on the default Contributors group for pipeline commits and changes, since it automatically grants full rights to build pipelines.

Show answer and explanation

Correct answer: A

Explanation

In Azure DevOps, you can use built-in groups and fine-grained permissions to meet specific requirements. Assigning DevOps Engineers to elevated permissions groups ensures that only they can manage pipelines, while configuring the Dev team� permissions at a project or pipeline level allows them to queue builds. All others can be restricted to viewing pipeline runs. Refer to Microsoft� documentation on setting permissions at the project, team, and object level for best practices: https://learn.microsoft.com/en-us/azure/devops/organizations/security/permissions.

  • A. Correct.

    Correct. Placing DevOps Engineers in a group with administrator-level permissions on pipelines ensures only they can modify or delete pipelines. Granting the Dev team 'Queue builds' allows them to run existing pipelines without editing them, and giving all other employees 'View builds' ensures they can only see results.

  • B. Incorrect.

    Incorrect. While a custom group for DevOps Engineers is useful, giving all Dev team members 'Edit build pipeline' violates the requirement to ensure pipeline modifications are restricted to DevOps Engineers only.

  • C. Incorrect.

    Incorrect. Granting all contributors 'Edit build pipeline' displays a common misconception that repository permissions alone can control pipeline actions�pipeline permissions must be set properly to restrict who can edit or delete pipelines.

  • D. Incorrect.

    Incorrect. The default Contributors group in Azure DevOps typically has more permissions than needed in this scenario. Additional fine-grained permissions are necessary to control build pipeline administration and operations.

Timed practice exam

Take a AZ-400 practice test under exam conditions

70 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam