exam questions

Exam AZ-400 All Questions

View all questions & answers for the AZ-400 exam

Exam AZ-400 topic 4 question 38 discussion

Actual exam question from Microsoft's AZ-400
Question #: 38
Topic #: 4
[All AZ-400 Questions]

You are designing the security validation strategy for a project in Azure DevOps.
You need to identify package dependencies that have known security issues and can be resolved by an update.
What should you use?

  • A. Octopus Deploy
  • B. Jenkins
  • C. Gradle
  • D. SonarQube
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
dollarpo7
Highly Voted 4 years, 7 months ago
Should be Sonarqube
upvoted 54 times
Pavlo
1 year, 12 months ago
A. Octopus Deploy B. Jenkins C. Gradle D. SonarQube<<<<<<<<<<<<<<<<<<<<<<<<
upvoted 1 times
...
...
Ahmed0
Highly Voted 4 years, 5 months ago
WTF who selected this answer ?
upvoted 30 times
larrymm
2 years, 10 months ago
At this point I just feel the do this on purpose cos wth
upvoted 2 times
...
hbergun
4 years, 3 months ago
Maybe Math.Random
upvoted 42 times
jojom19980
3 years, 11 months ago
maybe, hh, you are right
upvoted 2 times
...
...
...
GPRai
Most Recent 11 months, 2 weeks ago
Selected Answer: D
SonarQube
upvoted 1 times
...
UrbanRellik
1 year ago
Selected Answer: D
I'd rather not explain myself. The answer is D, SonarQube.
upvoted 1 times
...
Ghauri07
1 year, 8 months ago
Selected Answer: A
Because Sonarqube did the code analysis
upvoted 1 times
...
yana_b
1 year, 9 months ago
Selected Answer: D
SonarQube
upvoted 1 times
...
resonant
1 year, 10 months ago
You can use SonarQube but arent you supposed to use MendBolt?
upvoted 1 times
...
klayytech
2 years, 3 months ago
Selected Answer: D
Octopus Deploy is a tool to manage releases and deploy the release it-self to the destination host, the Azure DevOps substitute is "Release PipeLine" SonarQube is for sure the correct answer
upvoted 6 times
...
syu31svc
2 years, 10 months ago
Selected Answer: D
This is D for sure
upvoted 3 times
...
Govcomm
2 years, 10 months ago
SonarQube
upvoted 1 times
...
Eltooth
3 years ago
Selected Answer: D
D is correct answer.
upvoted 2 times
...
UnknowMan
3 years, 1 month ago
Selected Answer: D
SonarQube can check for security licence
upvoted 1 times
...
rdemontis
3 years, 2 months ago
Selected Answer: D
I think correct answer id D. There is a plugin (dependency-check) for SonarQube that do exactly what it is required by the questions. Not a scan of the dependencies but a control based on known security issues https://github.com/dependency-check/dependency-check-sonar-plugin
upvoted 7 times
kennynelcon
2 years, 10 months ago
Thank You
upvoted 1 times
...
...
Optimist_Indian
3 years, 3 months ago
Got this question in Feb-2022 exam (scored 910+). Answer : SonarQube.
upvoted 5 times
...
durel
3 years, 4 months ago
Selected Answer: D
should be D
upvoted 1 times
...
Art3
3 years, 4 months ago
Selected Answer: D
Obviously D.
upvoted 1 times
...
Pankaj78
3 years, 5 months ago
Selected Answer: D
Octopus deploy is solely responsible for automated deployment management
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...