nerdexam
MicrosoftMicrosoft

AZ-400 · Question #365

AZ-400 Question #365: Real Exam Question with Answer & Explanation

To configure App1 to use a service principal in Azure AD, you must follow three sequential steps: first, register the application by creating an app registration in Azure AD, then generate credentials by adding a client secret to that app registration, and finally configure App1

Submitted by stefanr· Mar 6, 2026Implement an authentication and authorization strategy - specifically configuring application identities using Azure AD service principals as part of DevOps pipeline and application security integration.

Question

Case Study 3 - Woodgrove Bank Overview General Overview Woodgrove Bank is a financial services company that has a main office in the United Kingdom. Technical Requirements and Planned Changes Planned Changes Woodgrove Bank plans to implement the following project management changes: Implement Azure DevOps for project tracking. Centralize source code control in private GitHub repositories. Implement Azure Pipelines for build pipelines and release pipelines. Woodgrove Bank plans to implement the following changes to the identity environment: Deploy an Azure AD tenant named woodgrovebank.com. Sync the Active Directory domain to Azure AD. Configure App1 to use a service principal. Integrate GitHub with Azure AD. Woodgrove Bank plans to implement the following changes to the core apps: Migrate App1 to ASP.NET Core. Integrate Azure Pipelines and the third-party build tool used to develop App2. Woodgrove Bank plans to implement the following changes to the DevOps environment: Deploy App1 to Azure App Service. Implement source control for the DB1 schema. Migrate all the source code from TFS1 to GitHub. Deploy App2 to an Azure virtual machine named VM1. Merge the POC branch into the GitHub default branch. Implement an Azure DevOps dashboard for stakeholders to monitor development progress. Technical Requirements Woodgrove Bank identifies the following technical requirements: The initial databases for new environments must contain both schema and reference data. An Azure Monitor alert for VM1 must be configured to meet the following requirements: - Be triggered when average CPU usage exceeds 80 percent for 15 minutes. - Calculate CPU usage averages once every minute. The commit history of the POC branch must replace the history of the default branch. The Azure DevOps dashboard must display the metrics shown in the following table. Access to Azure DevOps must be restricted to specific IP addresses. Page load times for App1 must be captured and monitored. Administrative effort must be minimized. Drag and Drop Question You need to configure authentication for App1. The solution must support the planned changes. Which three actions should you perform in sequence? To answer, move all actions from the list of actions to the answer area and arrange them in the correct order. Answer:

Explanation

To configure App1 to use a service principal in Azure AD, you must follow three sequential steps: first, register the application by creating an app registration in Azure AD, then generate credentials by adding a client secret to that app registration, and finally configure App1 with the application (client) ID and the secret so it can authenticate using the service principal identity. This is the standard OAuth 2.0 client credentials flow for service principal authentication in Azure AD.

Topics

#Azure Active Directory#Service Principal#App Registration#Azure Identity Management

Community Discussion

No community discussion yet for this question.

Full AZ-400 PracticeBrowse All AZ-400 Questions