AZ-400 · domain
Design and implement a source control strategy
This domain covers how you choose and enforce branching, repository, and trigger strategies in Azure Repos and GitHub, then wire them into Azure Pipelines. Questions are scenario-based: pick the right trigger, workflow, or repo layout for a stated team size, migration, or monorepo constraint, and justify it against alternatives.
Focused practice
Practice Design and implement a source control strategy questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Design and implement a source control strategy
Be able to pick and configure the right trigger, branching workflow, and branch policy for a given scenario in Azure Repos or GitHub. The single most important thing: match the trigger type to the event — PR validation uses branch policy build validation, not a plain CI trigger.
Selecting PR triggers (branch policy build validation vs. CI triggers on main) in Azure Pipelines YAML
Choosing Git branching workflows (feature, trunk-based, GitFlow, release) to reduce merge conflicts during TFVC migration
Configuring path filters and pipeline triggers so monorepos build only changed projects
Applying branch policies: required reviewers, build validation, linked work items, comment resolution, merge strategy
Watch out for
Common Design and implement a source control strategy exam traps
- ▸Confusing a pull request trigger with a CI trigger on the target branch; PR validation needs a branch policy build, not just a trigger.
- ▸Assuming GitFlow suits small teams doing continuous delivery; it adds long-lived branches and merge overhead that trunk-based avoids.
- ▸Forgetting path filters in monorepo pipelines, so every commit rebuilds all projects and wastes agent time.
Question index
All Design and implement a source control strategy questions (74)
Click any question to see the full explanation, or start a practice session above.
Your team uses GitHub for source control. You need to ensure that sensitive data, such as connection strings, is never committed to the repository. Which tool should you use?
Easy2Your Azure DevOps project contains a Git repository with multiple branches. You need to ensure that code reviews are mandatory for all pull requests targeting the 'release' branch. Additionally, the build pipeline must pass before merging. How should you configure branch policies?
Medium3Which TWO approaches can you use to enforce consistent commit message formatting across your organization? (Choose two.)
Hard4You have the above branch policy configuration for the main branch. A developer pushes a new commit to an existing pull request. What happens?
Hard5Your organization uses Azure Repos and wants to implement a Git branching strategy that supports continuous delivery with hotfix capabilities. Which THREE practices should be part of the strategy?
Medium6Your organization uses GitHub Enterprise and wants to enforce that all repositories have a consistent CODEOWNERS file. Which approach should you use to centrally manage this?
Hard7Your organization uses GitHub for source control. You need to implement a secure source control strategy that prevents secrets from being exposed and ensures code quality. Which THREE practices should you implement?
Hard8Your Azure Pipeline is configured as shown in the exhibit. A developer pushes a commit to a feature branch named 'feature/new-login' and creates a pull request targeting the main branch. Which pipeline runs will be triggered?
Hard9Your organization uses Azure Repos and requires that all code changes pass a security scan before merging. The scan is run as a build validation policy. However, the scan takes 30 minutes and developers often bypass it by pushing directly to main. How can you enforce the policy for all changes?
Hard10Your company uses GitHub for source control. The security team requires that all commits to the main branch be signed with an approved GPG key. Additionally, developers must use their corporate email for commits. You need to configure branch protection rules and repository settings to enforce these requirements. Which combination of settings should you use?
Hard11Which TWO benefits does using Git LFS (Large File Storage) provide? (Select TWO.)
Medium12Your team is using Git with Azure Repos. A developer accidentally committed a large binary file to the main branch. What is the recommended way to permanently remove it from the repository history?
Easy13Which TWO options are benefits of using Git LFS (Large File Storage) in a team environment? (Select TWO.)
Medium14Refer to the exhibit. You are reviewing a branch protection rule for the main branch of a GitHub repository. A developer complains that after pushing new commits to an existing pull request, the existing approvals from two reviewers are dismissed, and the pull request cannot be merged even though the CI checks pass. What is the most likely cause?
Hard15Your organization has multiple GitHub repositories that use shared workflows. You want to centrally manage these workflows and ensure they are always up to date. What is the recommended approach?
Hard16You are debugging a recent issue introduced in the main branch. Based on the exhibit, which command would you run to revert the 'Fix login bug' commit while preserving the merge commit?
Hard17Your team uses Azure Repos and wants to prevent developers from committing secrets and large binary files into a shared repository. You plan to enforce this with client-side and server-side controls. Which two actions should you take? (Choose two.)
Medium18Which THREE practices are recommended for managing secrets in a Git repository? (Select THREE.)
Hard19Your team uses Git for source control. You want to maintain a clean commit history on the main branch by avoiding merge commits. Which TWO merge strategies in a pull request achieve this?
Easy20Your team uses GitHub and wants to automatically label pull requests based on the content of the changes (e.g., 'frontend' for changes in /frontend folder, 'backend' for /backend). Which approach should you use?
Hard21Refer to the exhibit. You have a branch policy JSON for Azure Repos. Which statement about this policy is correct?
Medium22Your team uses Azure DevOps and wants to enforce that all changes to the main branch go through a pull request process with at least two approvals. They also want to prevent contributors from approving their own pull requests. Which branch policy settings should they use?
Easy23Your team uses GitHub Flow. A developer pushes a feature branch to origin and creates a pull request to main. After review and approval, the pull request is merged. Which branch should the developer delete after the merge to maintain a clean repository?
Medium24Your team uses Azure Repos and has a repository with a large number of binary files (e.g., images, compiled libraries) that bloat the repository size. You want to reduce clone times and storage usage while still maintaining version history for those files. Which approach should you recommend?
Medium25You have a GitHub repository with a GitHub Actions workflow that builds a .NET application. The workflow should only run when changes are pushed to the main branch, but it currently runs on every push to any branch. How should you fix the workflow trigger?
Easy26Your team uses Azure Repos and needs to prevent secrets from being committed to the repository. Which built-in feature should you enable?
Medium27Which THREE practices are recommended for effective source control in a GitHub monorepo? (Choose three.)
Medium28You are reviewing the branch protection policy for the main branch in an Azure DevOps repository. Based on the exhibit, what happens when a stale review exists on a pull request after new changes are pushed?
Medium29Which TWO actions should you take to implement Git-based source control for a large enterprise with multiple teams and a single repository (monorepo)? (Select TWO.)
Hard30Your company is a startup developing a mobile application with a small team of 5 developers. You use GitHub Free and want to implement a simple but effective branching strategy that supports continuous delivery. The team wants to release new features every week and be able to hotfix critical bugs quickly. They currently have a main branch and feature branches, but sometimes features are merged to main before they are fully tested, causing issues. You need to recommend a strategy that minimizes risk while keeping the process lightweight. The team does not want to use long-lived branches. What should you recommend?
Medium31Your team uses Git and wants to ensure that all commits follow a consistent message format. Which approach should you use?
Easy32Your team is using GitHub Flow for a web application. Developers create feature branches from main, make changes, and open pull requests. Recently, several pull requests were merged without required reviews because the branch protection rules were not enforced on the main branch. What should you do to ensure all pull requests to main require at least one reviewer?
Medium33Your organization uses GitHub and wants to implement a monorepo strategy for multiple related projects. Which approach best optimizes CI/CD pipeline performance by only building projects that have changed?
Hard34Your organization is adopting a trunk-based development strategy with short-lived feature branches. Which branch policy should you enforce to ensure that code is integrated frequently and conflicts are minimized?
Easy35Which THREE are common Git branching strategies used by development teams? (Select THREE.)
Easy36Your team is migrating from TFVC to Git in Azure Repos. Developers frequently work on the same files simultaneously. Which Git workflow should you recommend to minimize merge conflicts?
Hard37Which THREE practices are recommended when implementing a Git branching strategy for a team using Azure Repos?
Hard38You receive a webhook notification from Azure Pipelines with the above payload. The build for the 'feature/logging' branch failed. You want to automatically create a work item to track the fix. What should you configure in Azure DevOps?
Medium39Your development team uses GitHub Enterprise and wants to automatically synchronize code from a public GitHub repository to their private repository every morning. What feature should they use?
Easy40Your company is migrating from TFVC to Git in Azure Repos. The repository contains a large number of binary files (e.g., .dll, .exe) that are frequently updated. You need to minimize repository size and clone time. What should you include in your migration plan?
Hard41Your team is standardizing on Azure Repos for a new project. Developers must be able to work on features in isolation and merge completed work back into the mainline, while keeping the mainline always buildable. Which branching strategy should you recommend as the baseline?
Easy42Your team uses a monorepo in Azure Repos. Developers frequently commit directly to the main branch, causing build failures. You need to enforce a policy that requires all changes to go through pull requests with at least one reviewer. What should you configure?
Medium43Which TWO Git operations are considered dangerous and should be used with caution because they rewrite history? (Select TWO.)
Easy44Your team uses Git with a trunk-based development strategy. They want to ensure that all code changes are integrated into the main branch at least once a day, and that branch lifetimes are short. Which practice best supports this?
Easy45Your team maintains a repository in Azure Repos. A release engineer needs to be able to create and push tags to the repository for production releases, but must NOT be able to push commits directly to any branch. Which configuration should you implement to meet this requirement?
Medium46Your team uses Azure Repos with a Git branching strategy. You need to ensure that all changes to the release branch are reviewed by at least two approvers and that builds succeed before merging. Which TWO branch policy settings should you enable?
Medium47Your team uses GitHub and wants to automatically link pull requests to work items in Azure Boards. What should you configure?
Medium48Your team uses a monorepo in Azure Repos with multiple microservices. Developers frequently report merge conflicts due to long-lived feature branches. Which branching strategy minimizes merge conflicts while supporting continuous integration?
Medium49Refer to the exhibit. An Azure DevOps pipeline has the YAML configuration shown. A developer creates a pull request from a feature branch to the develop branch. What will happen?
Medium50Your team uses GitHub and wants to enforce that all commits to the main branch are signed with a GPG key. Which branch protection rule should you configure?
Easy51Your organization uses GitHub for source control. You need to enforce that all pull requests require at least one approval and that branches must be up to date with the base branch before merging. Which branch protection rule settings should you enable?
Easy52Which TWO actions help reduce the size of a Git repository over time?
Medium53Refer to the exhibit. An Azure DevOps administrator has configured the branch policy for the main branch as shown. A developer attempts to push a commit directly to the main branch. What will happen?
Medium54Your team uses a monorepo in Azure Repos with multiple feature branches. You notice that merge conflicts frequently occur because developers are working on the same files. You want to reduce conflicts and improve collaboration. Which branching strategy should you recommend?
Medium55Your organization uses Azure Repos and has multiple Git repositories that share common code. You want to enable code reuse across these repositories without duplicating code. Which strategy should you use?
Medium56You need to enforce that every commit in your repository is associated with a work item in Azure Boards. Which mechanism should you use?
Easy57Which TWO actions should you take to proactively protect your repository from accidentally committing secrets? (Choose two.)
Easy58Your organization uses GitHub Copilot for pull request summaries. A developer notices that the AI-generated summary is inaccurate. Which step should the developer take to improve the quality of future summaries?
Medium59Refer to the exhibit. A developer runs 'git log --oneline --graph --decorate' and sees the output. Which Git workflow does this history most closely represent?
Hard60Your team uses Git for source control. A developer accidentally committed a large binary file (500 MB) to the main branch. The push succeeded but other team members are now complaining about slow fetch times. What is the most efficient way to remove the file from the repository history?
Medium61Your team uses GitHub Flow and wants to ensure that every pull request is reviewed by at least one team member. Which branch protection rule should you enable?
Easy62Your team uses GitHub for source control and wants to enforce that all pull requests into the main branch require at least two reviewers and must pass a status check from a CI pipeline. Which branch protection rule configurations should you apply?
Medium63You are designing a Git branching strategy for a large enterprise with multiple Azure DevOps projects. The strategy must support hotfixes for production releases, feature development in isolated branches, and release branches for stabilization. The team uses CI/CD pipelines that trigger on branch creation. You need to minimize merge conflicts and ensure that hotfix changes are propagated to all active branches. Which branching model should you recommend and how should you configure branch policies?
Hard64You are setting up a new GitHub repository for a project that requires strict access control. Only specific team members should be able to push to the main branch, but all team members should be able to create branches and open pull requests. What is the best way to achieve this?
Easy65Your organization uses Azure DevOps for a large-scale e-commerce platform. The source code is stored in a single Azure Repos Git repository with over 100 contributors. The current branching strategy is a modified GitFlow with main, develop, release, and hotfix branches. However, the team is experiencing frequent merge conflicts and long integration periods. You have been asked to redesign the branching strategy to support continuous integration and deployment (CI/CD) while ensuring high-quality releases. The new strategy must reduce merge conflicts, enable fast feedback, and support hotfixes. The team uses feature flags to manage incomplete features. Which branching strategy should you recommend?
Hard66Your team uses Azure Repos and wants to enforce that all commits to the release branch must be signed using GPG. Which branch policy should you enable?
Hard67You are designing a branching strategy for a microservices application with independent deployment cadences. The team wants to support continuous deployment to production from the main branch while allowing feature work to be isolated and tested. Which branching strategy best meets these requirements?
Hard68Your team is migrating from TFVC to Git in Azure Repos. You need to preserve the full history of the TFVC repository, including all branches and changesets. The TFVC repository is large (over 10 GB). Which tool should you use to perform the migration?
Easy69Your Azure DevOps repository contains a large binary file that is slowing down clone operations. Which Git feature should you use to reduce the clone time?
Easy70Your development team uses GitHub for source control. You want to automatically run a set of tests every time a pull request is opened against the main branch. What should you configure?
Easy71Your team uses Azure Pipelines to build and test code. You want to automatically trigger a pipeline when a pull request is created targeting the main branch. Which trigger should you configure?
Easy72Which TWO are valid reasons to use a monorepo?
Easy73Your team is migrating from TFVC to Git in Azure Repos. They want to preserve the history of all branches. Which migration tool should you use?
Medium74Your company uses Azure DevOps and has a large monorepo with multiple teams. Developers report that Git operations are slow due to the repository size. Which approach should you recommend to improve performance while maintaining a single repository?
HardOther domains
All AZ-400 exam domains
Frequently asked questions
- What does the Design and implement a source control strategy domain cover on the AZ-400 exam?
- Be able to pick and configure the right trigger, branching workflow, and branch policy for a given scenario in Azure Repos or GitHub. The single most important thing: match the trigger type to the event — PR validation uses branch policy build validation, not a plain CI trigger.
- How many questions are in this domain?
- This page lists all 74 Design and implement a source control strategy questions in the AZ-400 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Design and implement a source control strategy questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.