Courseiva
Develop a security and compliance planeasyMultiple SelectObjective-mapped

AZ-400 Develop a security and compliance plan Practice Question

Which TWO compliance frameworks are directly supported by Microsoft Purview Compliance Manager for Azure DevOps?

⚠ Common exam trap

Watch out — candidates often assume any major compliance framework (like HIPAA or PCI DSS) is directly supported, but Microsoft Purview Compliance Manager for Azure DevOps only provides pre-built templates for a specific subset of frameworks, including ISO 27001 and SOC 2, while others require custom assessments or are covered at the Azure platform level rather than the Azure DevOps service level.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

ISO 27001

Microsoft Purview Compliance Manager directly supports ISO 27001 and SOC 2 as built-in compliance templates for Azure DevOps. These frameworks are pre-configured with control mappings, assessment templates, and automated testing actions that align with Azure DevOps security and audit capabilities. This allows organizations to continuously monitor and manage compliance posture against these standards without manual configuration.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ISO 27001

    Why this is correct

    ISO 27001 is a widely adopted information security management standard, and Purview Compliance Manager includes a template that maps Azure DevOps controls to it. You can use this template to assess and manage your DevOps compliance posture against ISO 27001 requirements.

  • HIPAA

    Why it's wrong here

    HIPAA is a US healthcare regulation that applies to covered entities and business associates, but it is not a directly mapped compliance framework in Purview for Azure DevOps. While Azure itself has HIPAA attestation, Azure DevOps does not have a dedicated HIPAA template in Compliance Manager.

  • PCI DSS

    Why it's wrong here

    PCI DSS is a payment card industry security standard, but it is not directly mapped to Azure DevOps in Purview Compliance Manager. Azure DevOps does not have a specific PCI DSS template, though the underlying Azure platform may have relevant attestations.

  • FedRAMP High

    Why it's wrong here

    FedRAMP High is a US federal government cloud authorization that applies to cloud service providers, and Azure has a FedRAMP High authorization. However, Azure DevOps is not separately covered by a FedRAMP High template in Purview Compliance Manager, so it is not directly supported.

  • SOC 2

    Why this is correct

    SOC 2 is an auditing framework for service organizations that manage customer data, and Purview Compliance Manager includes a SOC 2 template that maps Azure DevOps controls. This allows you to evaluate and demonstrate compliance with SOC 2 trust services criteria.

About these practice questions

One of 823 original AZ-400 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-400 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-400 exam.