Courseiva

AZ-400 · topic practice

Develop a security and compliance plan practice questions

This domain covers securing Azure DevOps end to end: branch policies and permissions, secret storage in Azure Key Vault, service connections and managed identities, pipeline scanning tasks, and compliance evidence. Questions are scenario-based, asking you to choose the correct control, ordering of deployment steps, or configuration to satisfy a stated security mandate.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Develop a security and compliance plan

What the exam tests

What to know about Develop a security and compliance plan

Be able to design and configure a secure CI/CD flow: enforce branch policies, keep secrets in Key Vault, use managed-identity service connections, add scanning tasks, and gate environments with approvals and checks. The most important thing is least-privilege identity and secret handling across the pipeline.

Configuring branch policies and required reviewers to enforce code change approval

Storing secrets in Azure Key Vault and linking variable groups to pipelines

Using service connections with Microsoft Entra managed identities instead of stored credentials

Running security scanning tasks such as dependency and secret detection in build pipelines

Watch out for

Common Develop a security and compliance plan exam traps

  • ▸Confusing Azure Key Vault access policies with Azure RBAC, or granting pipeline identities excessive permissions
  • ▸Placing secrets in pipeline variables or YAML instead of Key Vault, exposing them in logs
  • ▸Assuming branch policies alone secure deployments without environment approvals or checks

Practice set

Develop a security and compliance plan questions

20 questions · select your answer, then reveal the explanation

Your organization uses Azure DevOps and Azure Key Vault to manage secrets. You have a pipeline that deploys a web app to Azure App Service. The pipeline uses a variable group linked to Key Vault to retrieve the database connection string. Recently, the build started failing with the error: 'Access to Key Vault is denied. Please ensure the service connection has Get and List permissions on secrets.' The service connection uses a service principal. You have verified that the service principal has the correct Key Vault access policy with Get and List permissions. What is the most likely cause of the failure?

A financial services company uses Azure DevOps and requires that all secrets (e.g., API keys, connection strings) be stored in Azure Key Vault. They have a pipeline that runs automated tests and deploys to staging. The pipeline uses a variable group linked to Key Vault to retrieve secrets. Recently, the pipeline failed with the error: 'Secret 'DbPassword' not found in Key Vault 'kv-prod'. Ensure the secret exists and the service principal has List permission.' The secret exists in the vault. What is the most likely cause?

Your organization uses Azure DevOps and Azure Policy to enforce compliance. You need to ensure that all Azure resources deployed by Azure DevOps pipelines have specific tags (e.g., CostCenter and Environment) applied. Which TWO approaches can achieve this? (Choose TWO.)

A company uses Azure DevOps and requires that all pipeline runs are audited and that sensitive information (e.g., passwords, keys) is never exposed in logs. Which TWO actions should you take? (Choose TWO.)

You are a DevOps engineer at a healthcare company that must comply with HIPAA. The company uses Azure DevOps with YAML pipelines to deploy a multi-tier application to Azure Kubernetes Service (AKS). The application stores sensitive patient data. The security team requires that all secrets (e.g., database passwords, API keys) must be stored in Azure Key Vault and never hardcoded in the pipeline. The pipeline currently uses a service principal (SP1) for AKS deployments. The pipeline has a variable group 'VG-Prod' linked to Key Vault 'KV-Prod' with secrets: 'DbPassword', 'ApiKey'. The pipeline runs successfully in non-production environments. However, when you run the pipeline for production, it fails at the stage that deploys to AKS with the error: 'Error: failed to get secret 'DbPassword' from Key Vault: Forbidden'. You have verified that the secret exists and the variable group is correctly linked. The service principal SP1 has the 'Get' and 'List' permissions on KV-Prod secrets. The AKS cluster is in a different subscription than the Key Vault. What is the most likely cause and how should you fix it?

A financial services company uses Azure DevOps to manage CI/CD pipelines for a critical application. The security team requires that all production deployments be approved by two different managers, and that the build artifacts are immutable and signed. Currently, the pipeline uses a manual approval gate with one approver and stores artifacts in Azure Artifacts. What should the DevOps engineer implement to meet the security requirements?

A company is adopting Azure DevOps and needs to ensure that all pipelines comply with regulatory standards. The security team wants to enforce that every build includes a security scan and that deployment to production requires approval from a compliance officer. Which TWO actions should the DevOps engineer take?

Your team uses GitHub Actions for CI/CD. Security policies require that secrets must be automatically rotated every 90 days. Which Azure DevOps feature should you integrate to enforce this requirement?

You are reviewing a compliance policy for Azure Pipelines. What does this policy enforce?

Exhibit

Refer to the exhibit.

```json
{
  "policy": {
    "name": "Require MFA for pipeline variables",
    "scope": [
      "variableGroup:MySecrets"
    ],
    "effects": {
      "requireMFA": {
        "on": "variableGroup:MySecrets",
        "action": "approve"
      }
    }
  }
}
```

You are reviewing an Azure DevOps permissions JSON. What access does the user 'user@contoso.com' have?

Exhibit

Refer to the exhibit.

```json
{
  "permissions": [
    {
      "role": "Reader",
      "identity": {
        "type": "group",
        "id": "a1b2c3d4-e5f6-7890-abcd-ef1234567890"
      },
      "scope": "project"
    },
    {
      "role": "Contributor",
      "identity": {
        "type": "user",
        "id": "user@contoso.com"
      },
      "scope": "build:Build-1"
    }
  ]
}
```

You are analyzing Azure DevOps audit logs with a KQL query. What is the purpose of this query?

Exhibit

Refer to the exhibit.

```kql
AzureDevOpsAuditLogs
| where TimeGenerated > ago(30d)
| where OperationName == "Project.Create"
| where ResultType == "Success"
| project TimeGenerated, ProjectName, ActorUPN
| summarize Count = count() by ActorUPN
| top 5 by Count desc
```

Your team uses GitHub Enterprise to manage source code. You need to implement a security and compliance plan that ensures all commits are signed using GPG keys and that secrets are scanned before code is merged. Which GitHub features should you combine?

Your organization uses Azure Key Vault to store secrets and certificates used in Azure Pipelines. You need to implement a security and compliance plan that ensures secrets are rotated automatically and access is audited. Which THREE actions should you take?

Your team is adopting GitHub Copilot for code generation. The compliance team requires that all code generated by AI is reviewed and that proprietary code is not used as training data. Which TWO settings should you configure in your GitHub organization?

Refer to the exhibit. Your organization has configured an Azure DevOps pipeline security setting that enforces a required template for all pipelines deploying to production and staging. The required template 'security-validation.yml' runs a series of security scans and compliance checks. A developer creates a new pipeline that deploys to a test environment, but the pipeline does not reference the required template. What will happen?

Exhibit

{
  "type": "Azure DevOps Pipeline Security",
  "settings": {
    "enforceRequiredTemplate": true,
    "requiredTemplate": "security-validation.yml",
    "scope": ["production", "staging"]
  }
}

Your organization uses Microsoft Defender for Cloud to monitor Azure resources. The compliance team needs to ensure that all Azure DevOps projects have their pipelines scanned for security issues before deployment. Which integration should you use?

Question 17hardmultiple choice
Read the full NAT/PAT explanation →

Refer to the exhibit. You have configured a Conditional Access policy in Microsoft Entra ID to require MFA for Azure DevOps. However, users report that they can still access Azure DevOps without MFA when using a PAT for authentication. What is the most likely reason?

Exhibit

{
  "policy": {
    "name": "Require MFA for Azure DevOps",
    "type": "Conditional Access Policy",
    "assignments": {
      "users": "All users",
      "cloud_apps": "Azure DevOps",
      "conditions": {
        "client_apps": ["Browser", "Mobile apps and desktop clients"]
      },
      "grant_controls": {
        "built_in_controls": ["Mfa"]
      }
    }
  }
}

Your organization needs to ensure that all containers built in Azure Pipelines are scanned for vulnerabilities before being pushed to a container registry. Which step should you add to the pipeline?

Your company uses Microsoft Purview to manage data governance. You need to classify a new dataset containing personally identifiable information (PII) and apply a data loss prevention (DLP) policy. What should you do first?

You are deploying a web app to Azure App Service using Azure Pipelines. The security team requires that all secrets are stored in Azure Key Vault and retrieved at deployment time. What is the best approach?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Develop a security and compliance plan sessions

Start a Develop a security and compliance plan only practice session

Every question in these sessions is drawn from the Develop a security and compliance plan domain — nothing else.

Related practice questions

Related AZ-400 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the AZ-400 exam test about Develop a security and compliance plan?
Be able to design and configure a secure CI/CD flow: enforce branch policies, keep secrets in Key Vault, use managed-identity service connections, add scanning tasks, and gate environments with approvals and checks. The most important thing is least-privilege identity and secret handling across the pipeline.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Develop a security and compliance plan questions in a focused session?
Yes — the session launcher on this page draws every question from the Develop a security and compliance plan domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other AZ-400 topics?
Use the topic links above to move to related areas, or go back to the AZ-400 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the AZ-400 exam covers. They are not copied from any real exam or dump site.