easyMultiple Choice
Enforcing a Minimum of Two Security Team Approvals Before Merge
A company uses Azure DevOps to manage code. They want to enforce that all changes to the main branch must go through a pull request with at least two reviewers. What should they configure?
⚠ Common exam trap
Candidates often confuse repository permissions (which control access) with branch policies (which control workflow and quality gates), leading them to select Option C instead of the correct branch policy configuration.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Branch policy on the main branch
Branch policies in Azure DevOps allow you to enforce requirements on pull requests targeting a specific branch. By configuring a branch policy on the main branch, you can require a minimum number of reviewers (e.g., two) and mandate that all changes must go through a pull request. This ensures that no direct commits bypass the review process.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Branch policy on the main branch
Why this is correct
Branch policies on the main branch can enforce a minimum number of reviewers and require successful pull request reviews before merging, making them the standard mechanism to ensure code review compliance. They also block direct pushes, forcing all changes through the review process.
- ✗
Add a tag to the main branch
Why it's wrong here
Adding a tag to the main branch simply marks a point in history, typically for release versioning, and does not enforce any workflow or review requirements. Tags are static metadata and do not prevent commits or require approvals.
- ✗
Repository permissions
Why it's wrong here
Repository permissions govern user and group access levels (e.g., read, write, contribute) but do not enforce a required review process. Even with restricted permissions, a user with push rights can commit without a review unless branch policies are configured.
- ✗
Configure a service hook
Why it's wrong here
Service hooks in Azure DevOps are outbound HTTPS callbacks to external systems (e.g., Slack, Microsoft Teams, or custom endpoints) that fire asynchronously when events such as pull request creation or build completion occur. They are notifications only—the external system cannot mutate or gate Azure DevOps state, and there is no built-in mechanism for the hook to block merging or require approvals. Because they operate entirely outside the policy evaluation engine, they cannot enforce a mandatory code review process on the main branch.
Go deeper
Related to this question
Learn chapter
Final Review and Exam Preparation
Key term
Azure DevOps
Azure DevOps is a Microsoft service that provides development tools for planning, building, testing, and deploying software applications using automated pipelines and collaboration features.
Key term
Branch policy
A branch policy is a set of rules and conditions enforced on a Git branch to control how code changes are proposed, reviewed, and merged, ensuring code quality and protecting critical branches.
About these practice questions
This AZ-400 question is part of Courseiva's 696-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
8 more ways this is tested on AZ-400
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A development team uses Git for source control. They want to ensure that all code changes are reviewed before merging into the main branch. Which branch policy should they configure in Azure Repos?
easy- ✓ A.Configure a branch policy that requires a minimum number of reviewers and resolves all comments.
- B.Configure a branch policy that requires commit messages to follow a specific pattern.
- C.Configure a branch policy that requires a successful build.
- D.Configure a branch policy that requires linked work items.
Why A: Azure Repos branch policies allow you to enforce that pull requests require a minimum number of reviewers and that all comments are resolved before merging. This directly ensures that all code changes are reviewed and any feedback is addressed, meeting the team's requirement for mandatory code review before merging into the main branch.
Variation 2. A development team wants to ensure that all code changes are reviewed by at least two senior developers before merging into the main branch. They use Azure Repos. What should they configure?
medium- A.Enable the build validation policy on the branch.
- B.Set up a release pipeline with gated deployments.
- ✓ C.Configure a branch policy requiring a minimum number of reviewers.
- D.Add a status check policy using Azure Functions.
Why C: Azure Repos branch policies allow you to enforce a minimum number of reviewers on pull requests. By setting the 'Minimum number of reviewers' policy to 2, the team ensures that at least two senior developers must approve any code change before it can be merged into the main branch. This directly meets the requirement without involving build validation, release pipelines, or external function calls.
Variation 3. Your team wants to implement a policy that requires all pull requests to have at least one approval from a member of the 'Senior Developers' group before merging. Which mechanism should you use?
easy- A.Add a CODEOWNERS file that designates 'Senior Developers' as owners of all files.
- ✓ B.Create a branch policy on the target branch that requires a minimum number of reviewers from the 'Senior Developers' group.
- C.Configure the pull request dashboard to display required reviewers.
- D.Set up a build validation policy that runs a script to check approvals.
Why B: Azure Repos branch policies allow you to enforce required reviewers on pull requests. By creating a branch policy on the target branch that requires a minimum number of reviewers from the 'Senior Developers' group, you ensure that no pull request can be completed without at least one approval from that group. This directly meets the requirement without relying on file-level ownership or external scripts.
Variation 4. Your organization uses Azure DevOps Services. The development team uses feature branches and pull requests to merge changes into the main branch. You need to implement a policy that ensures every pull request has at least two approvals from the 'Senior Developers' group, and the build must succeed before merging. Additionally, any comment on the pull request must be resolved before merging. The policy should apply to the main branch only. You have already created the 'Senior Developers' group in Azure DevOps. What should you do?
medium- A.Configure the team's settings to require approvals for all pull requests.
- ✓ B.Add a branch policy on the main branch that requires a minimum of two reviewers from 'Senior Developers', a successful build, and that all comments are resolved.
- C.Set up a build validation policy on the main branch that runs the pipeline and fails if comments are unresolved.
- D.Configure the repository's pull request settings to require approvals and comment resolution.
Why B: Azure DevOps branch policies allow you to enforce specific requirements on pull requests targeting a branch. By configuring a branch policy on the main branch, you can require a minimum number of reviewers from a specific group (e.g., 'Senior Developers'), a successful build, and that all comments are resolved before merging. This directly meets all the stated requirements.
Variation 5. Your team uses Azure DevOps and wants to enforce that all work items must be linked to a pull request before merging. Additionally, the pull request must be approved by at least two reviewers. Which two branch policies should you enable?
medium- A.Automatically update work items
- ✓ B.Require a minimum number of reviewers
- ✓ C.Check for linked work items
- D.Build validation
- E.Comment resolution
Why B: Option B (Require a minimum number of reviewers) is correct because this branch policy lets you set the required reviewer count, so configuring it to two enforces that a pull request must be approved by at least two reviewers before it can complete. Option C (Check for linked work items) is correct because this policy blocks pull request completion unless at least one work item is linked, directly enforcing that all work items be associated with a pull request before merging. Option A (Automatically update work items) only changes the state of linked work items after a merge and does not require any link to exist, so it does not enforce the linking requirement. Option D (Build validation) triggers a build pipeline to validate the merge but has nothing to do with reviewer counts or work item links. Option E (Comment resolution) only requires that active pull request comments be resolved and does not enforce reviewer approvals or work item linkage.
Variation 6. Your team uses Azure DevOps and wants to enforce that all changes to the main branch go through a pull request process with at least two approvals. They also want to prevent contributors from approving their own pull requests. Which branch policy settings should they use?
easy- A.Enable 'Check for linked work items' and 'Require a minimum number of reviewers' set to 2, and enable 'Reset code reviewer votes when new changes are pushed'.
- B.Add the 'main' branch to the 'Required reviewers' list and add all developers as required reviewers.
- C.Enable 'Require a minimum number of reviewers' set to 2, and enable 'Build validation' with a required build.
- ✓ D.Enable 'Require a minimum number of reviewers' set to 2, and enable 'Allow users to approve their own changes' unchecked (or set to false).
Why D: It directly addresses both requirements: setting 'Require a minimum number of reviewers' to 2 enforces at least two approvals, and unchecking 'Allow users to approve their own changes' prevents contributors from approving their own pull requests. These are branch policy settings within Azure Repos that control the pull request workflow on the main branch.
Variation 7. Your team uses a monorepo in Azure Repos. Developers frequently commit directly to the main branch, causing build failures. You need to enforce a policy that requires all changes to go through pull requests with at least one reviewer. What should you configure?
medium- A.Configure a repository policy to require a pull request for all branches.
- B.Create a service hook to reject commits to main that are not from pull requests.
- ✓ C.Configure a branch policy on the main branch to require a minimum number of reviewers.
- D.Enable the 'Require a minimum number of reviewers' setting in the project settings.
Why C: Azure Repos allows you to configure branch policies on specific branches (like main) to enforce that all changes must come through pull requests and require a minimum number of reviewers. This directly addresses the need to prevent direct commits to main and ensure code review before merging.
Variation 8. Your Azure DevOps project uses Git for source control. You want to enforce that all code changes are reviewed before merging into the main branch. Which branch policy should you enable?
medium- A.Allow only comment resolution.
- B.Require a successful build before merging.
- C.Limit merge types to squash merge.
- ✓ D.Require a minimum number of reviewers.
Why D: The 'Require a minimum number of reviewers' branch policy in Azure DevOps enforces that a specified number of approvers must sign off before a pull request can be completed, directly satisfying the requirement that all code changes are reviewed before merging. This policy can be set on the main branch and optionally reset votes on new pushes. It is the standard mechanism for mandatory code review in Azure Repos.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-400 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-400 exam.