AZ-400 Develop a security and compliance plan • Set 2
AZ-400 Develop a security and compliance plan Practice Test 2 — 15 questions with explanations. Free, no signup.
Your company is migrating from on-premises TFS to Azure DevOps Services in the cloud. The security policy mandates that all access to Azure DevOps must go through a conditional access policy that requires multi-factor authentication (MFA) for users outside the corporate network. Additionally, the policy requires that service accounts (used for automated deployments) must use device-based authentication and cannot be interactive. You are configuring Microsoft Entra ID (formerly Azure AD) conditional access. The Azure DevOps organization is connected to the corporate Entra ID tenant. You have the following options:
Option A: Create a conditional access policy that applies to all users and service principals, requiring MFA for all cloud apps, and exclude the Azure DevOps app from the policy.
Option B: Create a conditional access policy that targets the Azure DevOps app, grant access requiring MFA for all users, and create a separate policy for service accounts that requires device compliance.
Option C: Create a conditional access policy that applies to the Azure DevOps app, requiring MFA for all users, and exclude service accounts by user group. Then create a separate policy for service accounts that requires a compliant device.
Option D: Use Azure DevOps IP address restrictions to block external traffic and rely on VPN for external users.
Which option best meets the requirements?
Choose an answer to begin — your selection is scored in the full session.
15 questions · instant feedback and full explanations after every question.