AZ-400 exam dumps

AZ-400 practice question 263 of 306

Designing and Implementing Microsoft DevOps Solutions. Professional level, Microsoft. Free question with the correct answer and a full explanation.

AZ-400 Question 263

Single answer

Your organization has an Azure DevOps pipeline that builds and pushes container images to Azure Container Registry (ACR). You want to configure Microsoft Defender for Cloud DevOps Security so that every newly pushed image is automatically scanned, and any vulnerabilities are reported in the Microsoft Defender for Cloud portal. Which of the following actions should you take first to ensure successful scanning and visibility of results?

  1. A

    Enable vulnerability scanning in Azure Container Registry using the Azure CLI.

  2. B

    Connect your Azure DevOps organization to Microsoft Defender for Cloud and enable Microsoft Defender for DevOps.

  3. C

    Add a custom scripting stage in the pipeline to upload container scan results directly into Azure Monitor.

  4. D

    Install the Azure Security Center extension into your Azure DevOps project under Project Settings.

Show answer and explanation

Correct answer: B

Explanation

To ensure container images built in Azure DevOps are scanned and reported in Microsoft Defender for Cloud, you must connect your DevOps organization to Defender for Cloud and enable Microsoft Defender for DevOps. This connection allows Defender for Cloud to identify and analyze container images as part of the development process. For more information, refer to Microsoft Defender for Cloud documentation on integrating Azure DevOps in the Environment Settings.

  • A. Incorrect.

    Option 1 (Enable vulnerability scanning in Azure Container Registry using the Azure CLI) is incorrect because enabling ACR vulnerability scanning through CLI alone does not automatically integrate or surface those results in Microsoft Defender for Cloud DevOps Security. While Azure Container Registry can be integrated with image vulnerability scanning, you must first establish the Microsoft Defender for Cloud DevOps connection.

  • B. Correct.

    Option 2 (Connect your Azure DevOps organization to Microsoft Defender for Cloud and enable Microsoft Defender for DevOps) is correct. This is the required first step to ensure your DevOps pipelines and repositories are recognized by Defender for Cloud. By enabling Microsoft Defender for DevOps in Defender for Cloud, you can configure security checks on your container images and see the results in the Defender for Cloud portal.

  • C. Incorrect.

    Option 3 (Add a custom scripting stage in the pipeline to upload container scan results directly into Azure Monitor) is incorrect because uploading scan results to Azure Monitor does not automatically integrate those findings with Microsoft Defender for Cloud. Defender for Cloud needs a native connection to DevOps environments rather than a custom script approach.

  • D. Incorrect.

    Option 4 (Install the Azure Security Center extension into your Azure DevOps project under Project Settings) is incorrect because simply installing an extension for Azure DevOps does not set up the end-to-end scanning and reporting integrations. The main configuration must be initiated within Microsoft Defender for Cloud by connecting Azure DevOps and turning on Defender for DevOps.

Timed practice exam

Take a AZ-400 practice test under exam conditions

70 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam