AZ-400 Develop a security and compliance plan Practice Question
Which TWO compliance frameworks are directly supported by Microsoft Purview Compliance Manager for Azure DevOps?
⚠ Common exam trap
Watch out — candidates often assume any major compliance framework (like HIPAA or PCI DSS) is directly supported, but Microsoft Purview Compliance Manager for Azure DevOps only provides pre-built templates for a specific subset of frameworks, including ISO 27001 and SOC 2, while others require custom assessments or are covered at the Azure platform level rather than the Azure DevOps service level.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
ISO 27001
Microsoft Purview Compliance Manager directly supports ISO 27001 and SOC 2 as built-in compliance templates for Azure DevOps. These frameworks are pre-configured with control mappings, assessment templates, and automated testing actions that align with Azure DevOps security and audit capabilities. This allows organizations to continuously monitor and manage compliance posture against these standards without manual configuration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
ISO 27001
Why this is correct
ISO 27001 is a widely adopted information security management standard, and Purview Compliance Manager includes a template that maps Azure DevOps controls to it. You can use this template to assess and manage your DevOps compliance posture against ISO 27001 requirements.
- ✗
HIPAA
Why it's wrong here
HIPAA is a US healthcare regulation that applies to covered entities and business associates, but it is not a directly mapped compliance framework in Purview for Azure DevOps. While Azure itself has HIPAA attestation, Azure DevOps does not have a dedicated HIPAA template in Compliance Manager.
- ✗
PCI DSS
Why it's wrong here
PCI DSS is a payment card industry security standard, but it is not directly mapped to Azure DevOps in Purview Compliance Manager. Azure DevOps does not have a specific PCI DSS template, though the underlying Azure platform may have relevant attestations.
- ✗
FedRAMP High
Why it's wrong here
FedRAMP High is a US federal government cloud authorization that applies to cloud service providers, and Azure has a FedRAMP High authorization. However, Azure DevOps is not separately covered by a FedRAMP High template in Purview Compliance Manager, so it is not directly supported.
- ✓
SOC 2
Why this is correct
SOC 2 is an auditing framework for service organizations that manage customer data, and Purview Compliance Manager includes a SOC 2 template that maps Azure DevOps controls. This allows you to evaluate and demonstrate compliance with SOC 2 trust services criteria.
Go deeper
Related to this question
Learn chapter
Introduction to DevOps and Azure DevOps
Key term
DevOps
DevOps is a set of practices that combines software development (Dev) and IT operations (Ops) to shorten the development lifecycle and deliver high-quality software continuously.
Key term
Azure DevOps
Azure DevOps is a Microsoft service that provides development tools for planning, building, testing, and deploying software applications using automated pipelines and collaboration features.
About these practice questions
One of 823 original AZ-400 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-400 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-400 exam.