Courseiva

Enforcing GPG-Signed Commits Without Blocking SSH-Authenticated Developers

An organization uses Azure Repos with multiple Git repositories. They want to enforce that all commits to the main branch are signed using GPG keys. Which combination of actions is required to enforce commit signing?

⚠ Common exam trap

Test-takers frequently confuse authentication methods (SSH keys, PATs) with commit signing (GPG keys), leading candidates to select options that address access control rather than cryptographic integrity.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure branch policy to require signed commits and have developers configure Git to sign commits with their GPG key.

Azure Repos supports a branch policy that requires commits to be signed, and developers must configure Git to sign commits with their GPG key using `git config --global user.signingkey` and `git commit -S`. This ensures that only signed commits are accepted into the main branch, enforcing non-repudiation and integrity.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure branch policy to require signed commits and have developers add their SSH public key to Azure Repos.

    Why it's wrong here

    SSH public keys in Azure Repos are used for SSH authentication and identify the developer for git operations, but Azure Repos branch policies that require signed commits verify GPG or S/MIME signatures, not SSH keys. SSH keys do not provide the cryptographic commit signature that the policy checks for, so this configuration would not satisfy the requirement.

  • ✗

    Configure repository settings to require a personal access token (PAT) for each commit.

    Why it's wrong here

    A personal access token (PAT) is an authentication mechanism for Azure DevOps REST APIs and git HTTPS operations; it is not a signing key and cannot be used to create cryptographic commit signatures. Requiring a PAT for each commit only enforces authentication, not integrity or non-repudiation, and Azure Repos branch policies do not support PAT-based commit signing validation.

  • ✓

    Configure branch policy to require signed commits and have developers configure Git to sign commits with their GPG key.

    Why this is correct

    Azure Repos branch policies can enforce that every commit in a protected branch is signed, and developers must configure their local Git client to sign commits with a GPG key (e.g., set user.signingkey and commit.gpgsign=true). When a developer pushes a signed commit, Azure Repos verifies the GPG signature against the developer's configured public key, while the private key remains securely on the developer's machine.

  • ✗

    Use Azure Key Vault to store signing keys and configure Azure Repos to automatically sign commits.

    Why it's wrong here

    Azure Key Vault can store signing keys, but Azure Repos does not provide any automatic commit-signing service that would use those keys to sign commits on a developer's behalf. Commit signing must happen locally in the Git client using a private key accessible to the developer; the branch policy can only verify signatures after they are pushed, it cannot generate signatures server-side.

Go deeper

Related to this question

About these practice questions

Courseiva writes every AZ-400 question from scratch — 696 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

7 more ways this is tested on AZ-400

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Your organization uses GitHub Enterprise and requires that all commits to the main branch are signed with a GPG key verified by your organization. Developers are getting errors when pushing signed commits. What is the most likely cause?

hard
  • A.The branch protection rule requires a linear history.
  • ✓ B.The developer's GPG key is not uploaded to their GitHub account or not verified.
  • C.The developer's email in the commit does not match any email on their GitHub account.
  • D.The developer's SSH key is not added to their GitHub account.

Why B: GitHub requires that the GPG key used to sign a commit be uploaded to the user's GitHub account and marked as verified. If the key is missing or unverified, GitHub cannot confirm the signature's authenticity, causing the push to be rejected when branch protection rules enforce signed commits.

Variation 2. Your organization wants to enforce that all commits to the main branch are signed using GPG or S/MIME. Which GitHub feature should you enable?

easy
  • A.Use the GitHub API to check commit signatures after push.
  • ✓ B.Configure a branch protection rule that requires signed commits.
  • C.Enable the 'Include administrators' setting in branch protection.
  • D.Require SSH key authentication for all users.

Why B: GitHub branch protection rules include a 'Require signed commits' setting that enforces all commits pushed to the protected branch must be signed with a verified GPG or S/MIME key. This ensures commit integrity and non-repudiation directly at the repository level, without requiring external scripts or API calls.

Variation 3. Your organization uses GitHub and wants to enforce that all commits to the main branch are signed with a GPG key that is verified against the user's GitHub account. Additionally, you want to block unsigned commits even if the committer is a repository admin. Which configuration should you use?

hard
  • A.Add a pre-receive hook that rejects unsigned commits.
  • B.Enable 'Require signed commits' and set 'Include administrators' to false.
  • ✓ C.Enable 'Require signed commits' and set 'Include administrators' to true.
  • D.Enable 'Require signed commits' and configure web commit signing.

Why C: Enabling 'Require signed commits' in a GitHub branch protection rule, combined with setting 'Include administrators' to true, enforces that every commit pushed to the protected branch must be signed with a GPG key verified against the user's GitHub account, and this restriction applies even to repository administrators. This configuration blocks unsigned commits entirely, meeting the requirement to enforce signing for all users including admins.

Variation 4. Your team uses GitHub and wants to enforce that all commits to the main branch are signed with a GPG key. Which branch protection rule should you configure?

easy
  • A.Require pull request reviews before merging.
  • B.Require status checks to pass before merging.
  • C.Require linear history.
  • ✓ D.Require signed commits.

Why D: The 'Require signed commits' branch protection rule enforces that every commit pushed to the protected branch must be signed with a GPG key. This ensures cryptographic verification of the commit author's identity, directly addressing the requirement to enforce signed commits on the main branch.

Variation 5. Your team uses Azure Repos and wants to enforce that all commits to the release branch must be signed using GPG. Which branch policy should you enable?

hard
  • A.Limit merge types
  • B.Check for linked work items
  • C.Require a minimum number of reviewers
  • ✓ D.Require signed commits

Why D: Azure Repos branch policies include a 'Require signed commits' setting that enforces GPG signature verification on all commits pushed to the branch. When enabled, any commit without a valid GPG signature is rejected, ensuring the integrity and authenticity of the commit author.

Variation 6. Your team uses GitHub repositories and wants to ensure that all code changes are signed by a verified contributor before merging. Which branch protection rule should you enable?

easy
  • ✓ A.Require signed commits
  • B.Require pull request reviews before merging
  • C.Require linear history
  • D.Restrict who can push to matching branches

Why A: Requiring signed commits ensures that each commit is cryptographically verified using a GPG or S/MIME key linked to the contributor's GitHub account. This enforces non-repudiation and confirms the identity of the author, directly addressing the requirement that all code changes be signed by a verified contributor before merging.

Variation 7. Your team uses GitHub Enterprise with GitHub Actions. Compliance requires that all contributors sign commits with a verified GPG key. You have enabled 'Require signed commits' on the repository. However, a developer reports that their commits are being rejected even though they have configured a GPG key. The error says 'Commit must have a valid signature.' The developer's GPG key is listed in their GitHub account settings. What is the most likely cause?

easy
  • A.The developer's GPG key has expired.
  • B.The developer's GPG key is not uploaded to GitHub.
  • ✓ C.The developer's local Git email does not match the email associated with the GPG key in GitHub.
  • D.GitHub only supports S/MIME, not GPG.

Why C: GitHub verifies a GPG signature by matching the signing key's associated email (and key ID) against the commit's author/committer email. If the developer's local Git user.email does not match the email registered with the GPG key in GitHub, GitHub marks the signature as unverified and the 'Require signed commits' rule rejects the push with 'Commit must have a valid signature.' The key being present in GitHub settings is not sufficient — the email binding must also match.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-400 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-400 exam.