Courseiva

Retaining Pipeline Audit Logs for a Full Year to Satisfy SOC 2

Your team uses Azure Pipelines and needs to comply with SOC 2 requirements. Which TWO features should you use to meet audit log requirements? (Select TWO.)

⚠ Common exam trap

A common mix-up: candidates confuse security controls (like network security groups or secret rotation) with audit logging features, mistakenly thinking any security measure fulfills audit log requirements, when only dedicated logging and log export features satisfy SOC 2 audit trail mandates.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable Azure DevOps audit logging

Azure DevOps audit logging (Option C) captures a detailed, immutable record of events such as pipeline runs, permission changes, and access attempts, which is essential for SOC 2 audit log requirements. Streaming these logs to Azure Monitor Log Analytics (Option E) enables long-term retention, advanced querying, and alerting, satisfying the need for secure log storage and monitoring.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure network security groups to block public access

    Why it's wrong here

    Network security groups (NSGs) are Azure networking constructs that filter inbound and outbound traffic to subnets or NICs; they do not capture or retain user-level action logs for Azure DevOps, so they have no bearing on SOC audit evidence collection.

  • ✗

    Automate secret rotation for service connections

    Why it's wrong here

    Automating secret rotation for service connections is a crucial credential-hygiene practice that reduces the risk of compromised pipeline authentication, but it does not generate or preserve an audit trail of who performed which DevOps actions, so it fails the SOC logging requirement.

  • ✓

    Enable Azure DevOps audit logging

    Why this is correct

    Enabling Azure DevOps audit logging records user and service principal actions across the organization, such as pipeline creation, permission changes, and policy edits, into the Audit log, which is the foundational mechanism for meeting SOC compliance evidence requirements.

  • ✗

    Create service principals for pipeline authentication

    Why it's wrong here

    Creating service principals for pipeline authentication establishes secure, non-interactive identities for service connections or scripts, but service principals themselves do not emit audit events; only enabling audit logging captures their actions, so this measure alone does not satisfy SOC logging obligations.

  • ✓

    Stream audit logs to Azure Monitor Log Analytics

    Why this is correct

    Streaming Azure DevOps audit logs to Azure Monitor Log Analytics via a diagnostic setting enables long-term retention, centralized querying, alerting, and correlation with other Azure resources, which transforms raw audit data into the persistent, analyzable evidence that SOC audits require.

About these practice questions

One of 696 original AZ-400 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on AZ-400

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Your organization uses Azure DevOps with multiple teams. You are tasked with creating a security and compliance plan. The environment includes: Azure Repos for source control, Azure Pipelines for CI/CD, and Azure Artifacts for package management. Requirements: 1) All code changes to the main branch must be reviewed by at least one member of the security team. 2) Deployment to production requires approval from a manager. 3) Secrets must be stored securely and rotated every 90 days. 4) Pipeline logs must be retained for 1 year for audit purposes. You have configured branch policies requiring a minimum number of reviewers and mandatory security team review. For production deployments, you have added a manual approval gate. Secrets are stored in Azure Key Vault with automatic rotation. However, the audit team reports that pipeline logs are only retained for 30 days. You need to extend log retention to 1 year. What should you do?

hard
  • A.Export pipeline logs to Azure Blob Storage and set a lifecycle policy to retain for 365 days.
  • B.Configure diagnostic settings in Azure Monitor to stream pipeline logs to a Log Analytics workspace.
  • ✓ C.In Azure DevOps project settings, navigate to Pipelines > Retention and releases, and set the retention policy to 365 days.
  • D.Enable Azure DevOps audit logs and export them to a Log Analytics workspace with a 365-day retention.

Why C: In Azure DevOps, pipeline retention policies for runs are configured at the project level under Project Settings > Pipelines > Retention and releases. Setting the retention to 365 days will keep pipeline run records and logs for one year. Option A is incorrect because exporting pipeline logs to Azure Blob Storage is not a built-in feature; pipeline logs are retained according to DevOps retention policies. Option B is incorrect because diagnostic settings in Azure Monitor stream Azure resource logs, not Azure DevOps pipeline logs. Option D is incorrect because audit logs capture events like changes to policies, not pipeline execution logs, and they have separate retention settings.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-400 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-400 exam.