What the AZ-400 exam actually tests and how to prepare

The AZ-400 is the DevOps Engineer Expert certification from Microsoft. It builds on AZ-104 or AZ-204. The exam covers designing and implementing strategies for collaboration, code, infrastructure, security, monitoring, and continuous feedback. You need to understand how these pieces fit together in a real Azure environment, not just define them. I took this exam twice. The first time I failed because I treated it like a memorization test. The second time I passed because I started thinking about it as a scenario-based workflow problem. That shift changed everything.

Az 400 Study Guide resources that actually help

There is no single official study guide from Microsoft that covers the breadth of this exam. The closest thing is the official skills measure document on Microsoft Learn. It lists every topic area and how heavily each is weighted. Print it out. Use it as your primary checklist. Beyond that, I relied on a mix of Microsoft Learn modules, Pluralsight courses, and a few community-driven practice exams. The practice exams are useful but imperfect. Some questions are poorly worded or outdated. Treat them as practice for the format, not as a guarantee of what will appear on the actual test. My go-to resource was Microsoft Learn's own DevOps paths. They are free, they are current, and they align closely with the exam objectives. I spent about 60 to 80 hours working through the materials before I felt ready.

One specific problem I ran into: The exam asks a lot about Azure Policy and its integration with GitOps workflows, especially when using Flux configuration. The official docs describe the feature well, but they do not walk you through the common edge case where a policy assignment blocks a GitOps sync even when the policy itself is correctly defined. I encountered this when building a lab environment. The workaround was to create an exclusion in the policy assignment targeting the namespace where the Flux controller runs, then verify the sync status directly in the Kubernetes cluster rather than relying on the portal status. I had to figure this out by setting up a real AKS cluster with Argo CD, not from reading about it.

How the exam questions are structured

The questions are mostly scenario-based. You get a description of a company, its current setup, and a problem it wants to solve. Then you pick the best answer from four options. The trick is that multiple answers might seem correct. The exam wants the *best* answer given the constraints described. For example, you might see a scenario where a company wants to deploy infrastructure using IaC and also needs compliance auditing. Both Azure Policy and Azure Blueprints could seem right. The question will include details that point toward one over the other. If it emphasizes governance at scale across multiple subscriptions and mandates, Blueprints is usually the answer. If it focuses on enforcing specific resource configurations at deployment time, Policy is the answer. Another thing to note: some questions reference legacy services that Microsoft has deprecated or renamed. The exam occasionally includes questions about Azure DevOps Services that use older terminology. Stick to current documentation when researching, but be aware that the exam might use terms like "release pipeline" even though Microsoft now calls them "deployment jobs" within a single pipeline.

Key areas to focus on

Source control and CI/CD pipelines. This is heavily weighted. You need to understand YAML vs. classic pipelines, how to structure multi-stage pipelines, and when to use environments and approval gates. Know how to implement canary deployments and blue-green strategies using Azure App Service and AKS. Infrastructure as Code. Terraform and Bicep are both relevant. You do not need to be an expert in either, but you should understand when to use each. Bicep is native to Azure and integrates tightly with Azure Resource Manager templates. Terraform is provider-agnostic and better when you need to manage resources outside Azure. Know how to use Terraform with Azure DevOps or GitHub Actions. Monitoring and feedback. Application Insights, Log Analytics, and Azure Monitor are essential. Understand how to set up dashboards, configure alerts, and use custom metrics. Also know how OpenTelemetry fits into the monitoring stack. Security and compliance. This includes Azure Key Vault integration, managed identities, vulnerability scanning in pipelines, and Sentinel for security monitoring. You should be able to explain how to set up a security scanning step in a pipeline using tools like Azure Security Center or Defender for Cloud. Artifacts and packaging. Azure Artifacts for NuGet and npm packages, container registries, and the role of Helm charts in Kubernetes deployments. Collaboration and feedback. How to use Azure Boards for work tracking, how to integrate feedback loops into pipelines, and how to set up automated testing and quality gates.

Common pitfalls candidates miss

Most people study the technologies in isolation. They learn what a pipeline is, then learn what a container is, then learn what Key Vault is. The exam does not test each technology separately. It tests how they interact. A single scenario might require you to chain together a trigger, a build step, a security scan, a deployment to AKS, and a monitoring check. If you have not practiced end-to-end flows, you will struggle with these questions. Another pitfall is underestimating the cloud-agnostic portions of the exam. Microsoft wants you to think beyond Azure-native tools. Questions about GitHub Actions, Terraform, and Kubernetes appear frequently even though this is an Azure exam. Do not skip those topics. A counter-intuitive insight: Many candidates assume that the "best" answer is always the most Azure-native solution. That is not true. Sometimes the best answer is the tool that best solves the stated problem, even if it is not built by Microsoft. If a scenario mentions a team already experienced with Terraform and asks for the most efficient way to manage infrastructure, the answer is Terraform, not Bicep. Read the question carefully.

What the AZ-400 Study Guide approach should look like

Start with the official skills measure. Map every objective to a learning resource. Build a study schedule that gives you at least two weeks of focused preparation. Take notes as you go. Write down the commands, the console paths, the portal navigation steps. Your hands need to know where things are. Then build something. Create an Azure DevOps project. Set up a YAML pipeline that builds, scans, and deploys a container to AKS. Add a manual approval gate. Configure Application Insights. Set up an alert. Break it. Fix it. This is where real learning happens. Reading about it does not replace doing it. For the practice questions, aim for consistent scores above 75 percent on third-party practice exams before scheduling the actual test. I scored around 68 percent on my first set of practice exams and jumped to 82 percent after a second review cycle focused on my weak areas.

I also found it helpful to review the Azure documentation for services I was less familiar with right before the exam. The documentation tends to use the same language and framing as the exam questions. It is not a shortcut, but it does help you get comfortable with the way Microsoft describes these tools.

The limitations of any study approach

No study guide will cover every question variant. The exam draws from a large question bank and updates it regularly. Practice exams are helpful but they cannot replicate the exact experience. Some questions on the actual exam reference features released only months before the test date. Staying current with Azure release notes helps. There is also a size limit to what any single guide can cover. The AZ-400 spans far more topics than most people expect. You do not need mastery of every tool. You need functional understanding across all domains and deeper knowledge in a few. Prioritize accordingly. If you find yourself stuck on a particular area, consider switching to hands-on labs or video walkthroughs rather than rereading documentation. The material is clear. The difficulty is usually in applying it to unfamiliar scenarios.

Final practical notes

Schedule the exam when you feel genuinely ready, not when you feel close. The buffer between "close" and "ready" is where most people land after a failed attempt. Use the free retake voucher if you fail. Microsoft offers it. Bring a valid ID. The testing center or proctoring setup will check it. Have your confirmation email ready. Show up early. The exam is two hours long. Manage your time. Flag difficult questions and move on. Come back to them later. This exam rewards practical understanding over rote memorization. The more you build and break things in Azure, the better prepared you will be.