AZ-400 exam dumps

AZ-400 practice question 235 of 306

Designing and Implementing Microsoft DevOps Solutions. Professional level, Microsoft. Free question with the correct answer and a full explanation.

AZ-400 Question 235

Single answer

Your organization has an Azure DevOps project and multiple private GitHub repositories. The marketing team needs read-only access to monitor work items and track progress in Azure DevOps without contributing code. Meanwhile, you have hired an external contractor who needs to push a bug fix to a single GitHub repository. As a DevOps engineer, what is the most appropriate way to configure access for the marketing team and the contractor while adhering to the principle of least privilege?

  1. A

    Assign Stakeholder access to marketing users in Azure DevOps and add the contractor as an outside collaborator with write access to the relevant GitHub repository.

  2. B

    Give the marketing team Basic access in Azure DevOps and add them as repository maintainers in GitHub for broader control.

  3. C

    Provide Project Collection Administrator access to the marketing team in Azure DevOps and add the contractor as an outside collaborator with read-only access in GitHub.

  4. D

    Create a custom access level for marketing in Azure DevOps and require the contractor to fork the GitHub repository without direct collaboration access.

Show answer and explanation

Correct answer: A

Explanation

In Azure DevOps, Stakeholder access is designed for users who need visibility into work items, queries, and dashboards but do not require code contribution rights. This level offers a cost-effective and secure way to involve non-technical stakeholders. In GitHub, adding the contractor as an outside collaborator with the appropriate permissions (typically write for bug fixes) ensures they can submit their changes without granting broader, unnecessary privileges. Refer to Microsoft Docs for more details on Azure DevOps access levels (https://learn.microsoft.com/azure/devops/organizations/security/access-levels) and GitHub documentation for outside collaborator roles (https://docs.github.com/en/github/setting-up-and-managing-billing-and-payments-on-github/adding-outside-collaborators-to-repositories-in-your-organization).

  • A. Correct.

    Correct: Stakeholder access in Azure DevOps allows non-technical team members to view boards, backlogs, and dashboards without the ability to push code, and outside collaborator with write access on GitHub grants only the necessary permissions for the contractor to contribute a bug fix.

  • B. Incorrect.

    Incorrect: Giving the marketing team Basic access provides code contribution rights they do not need, and making them maintainers in GitHub would grant more control than required.

  • C. Incorrect.

    Incorrect: Project Collection Administrator is the highest privilege level in Azure DevOps and far exceeds what the marketing team needs for simple progress tracking. Additionally, the contractor requires write access, not just read-only, to submit a bug fix in GitHub.

  • D. Incorrect.

    Incorrect: While a custom access level can be created in Azure DevOps, it is unnecessary because Stakeholder access already covers reporting and tracking needs. Forcing the contractor to fork and submit changes without collaboration access complicates the workflow unnecessarily.

Timed practice exam

Take a AZ-400 practice test under exam conditions

70 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam