AZ-400 exam dumps

AZ-400 practice question 264 of 306

Designing and Implementing Microsoft DevOps Solutions. Professional level, Microsoft. Free question with the correct answer and a full explanation.

AZ-400 Question 264

Select 2

You are a DevOps engineer at a company that wants to integrate Microsoft Defender for Cloud DevOps Security with Azure DevOps. The goal is to automatically scan your Infrastructure-as-Code (IaC) templates in the Azure DevOps repository for security vulnerabilities, exposing any misconfigurations directly in the Defender for Cloud portal. Which two steps should you perform first to properly configure this integration?

  1. A

    Enable the DevOps Security plan in Microsoft Defender for Cloud and connect your Azure DevOps organization from the Defender for Cloud console.

  2. B

    Add a PowerShell script in your build pipeline that manually calls the Microsoft Defender for Cloud CLI tools for each code change.

  3. C

    Create a service connection in Azure DevOps with Contributor-level permissions on the Azure subscription for each repository you want to scan.

  4. D

    Grant read access to the Microsoft Defender for Cloud DevOps application and complete the authorization process in the Defender for Cloud environment settings.

Show answer and explanation

Correct answers: A, D

Explanation

To configure Microsoft Defender for Cloud DevOps Security with Azure DevOps, you first enable the DevOps Security plan in your chosen subscription from the Defender for Cloud portal. Then, you connect your Azure DevOps organization so that Azure DevOps is authorized to share repository information with Defender for Cloud. This involves granting read permissions to the Defender for Cloud DevOps application. Once configured, Defender for Cloud can automatically scan your IaC templates for vulnerabilities and misconfigurations. For more details, see the Defender for Cloud documentation at https://learn.microsoft.com/azure/defender-for-cloud.

  • A. Correct.

    Correct. You must enable the DevOps Security plan under 'Environment settings' in the Microsoft Defender for Cloud portal. Then, connect your Azure DevOps organization so Defender for Cloud can automatically scan your IaC templates and display the results.

  • B. Incorrect.

    Incorrect. While using scripts can be part of a custom scanning approach, Defender for Cloud DevOps Security does not require you to manually call CLI tools for each code change. The recommended integration is done by enabling the plan and letting Defender for Cloud automatically handle scans.

  • C. Incorrect.

    Incorrect. You do not need to create a separate service connection with Contributor permissions for each repository just to enable scanning. Service connections are often used for deploying resources, but not strictly required for basic Defender for Cloud scanning configuration.

  • D. Correct.

    Correct. Defender for Cloud must have read access to your repositories so that it can scan the IaC templates. You authorize this in Defender for Cloud by granting the required permissions to the Microsoft Defender for Cloud DevOps application.

Timed practice exam

Take a AZ-400 practice test under exam conditions

70 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam