Courseiva

AZ-400 Develop a security and compliance plan Practice Question

Which TWO practices should you follow to ensure compliance with regulatory requirements (e.g., PCI DSS) when using Azure DevOps? (Choose two.)

⚠ Common exam trap

Test-takers frequently confuse 'audit logging' with a cost-saving measure (Option D) or think manual tracking (Option A) is acceptable, while the exam expects you to recognize that automated, immutable audit trails and enforced branch policies are the only reliable ways to meet regulatory compliance in a DevOps context.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable Azure DevOps audit logging to track changes to pipelines and policies.

Option C is correct because enabling Azure DevOps audit logging captures a tamper-evident trail of events such as pipeline modifications, policy changes, permission updates, and user access, which is essential for demonstrating compliance with regulatory frameworks like PCI DSS that require monitoring and traceability of changes to systems handling cardholder data. Option E is correct because branch policies enforce mandatory code reviews, minimum approver counts, and build validation before changes merge, providing the segregation of duties and change-control evidence that PCI DSS requires for modifications to production pipelines and code. Option A is not appropriate because manually tracking pipeline changes in a spreadsheet is error-prone, unauditable, and lacks the integrity and automation of native Azure DevOps audit logs. Option B is incorrect because unrestricted pipeline creation and modification violates the principle of least privilege and PCI DSS change-control requirements. Option D is incorrect because disabling audit logging removes the very evidence needed for compliance and directly contradicts regulatory monitoring obligations.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Manually track changes to pipelines in a spreadsheet.

    Why it's wrong here

    Spreadsheets are not tamper-evident and cannot generate the immutable audit trail PCI DSS requires; Azure DevOps already logs pipeline changes natively. Manual tracking is tempting for small teams documenting approvals, but it fails the automated, verifiable evidence regulators demand.

  • ✗

    Allow all users to create and modify pipelines without restrictions.

    Why it's wrong here

    Unrestricted pipeline creation lets any contributor alter build and release definitions, so a single commit could inject code that bypasses PCI DSS change-control and segregation-of-duties evidence. It is tempting because frictionless self-service pipelines suit fast-moving internal teams with no audit scope, where every engineer already holds production rights.

  • ✓

    Enable Azure DevOps audit logging to track changes to pipelines and policies.

    Why this is correct

    Audit logging records every change to pipelines, policies and permissions, producing the tamper-evident trail PCI DSS requires for accountability and forensic review. It satisfies the stem's regulatory compliance constraint by evidencing who altered build definitions and when, which access reviews and branch policies alone cannot demonstrate.

  • ✗

    Disable audit logging to reduce storage costs.

    Why it's wrong here

    Disabling audit logging removes the evidence trail PCI DSS mandates for change tracking and access monitoring, directly violating requirements. Cost-saving appeals to teams with tight budgets, yet logging is precisely what compliance frameworks require retained and reviewable.

  • ✓

    Use branch policies to enforce code reviews and approvals for all changes.

    Why this is correct

    Branch policies enforce mandatory reviewer approval before code merges, creating an auditable segregation-of-duties control that PCI DSS change-management requirements demand. Every pull request records who approved what and when, producing the tamper-evident trail auditors expect. This directly satisfies the stem's regulatory compliance constraint by preventing unreviewed changes reaching production.

About these practice questions

This AZ-400 question is part of Courseiva's 696-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-400 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-400 exam.